Bugtraq mailing list archives
XSS - CMS Made Simple v1.0.2
From: "Curtis Zimmerman" <curtis.zimmerman () gmail com>
Date: Mon, 25 Dec 2006 18:13:33 -0300
Product: CMS Made Simple v1.0.2 Class: XSS Website: http://www.cmsmadesimple.org Found by: L0j1k of D.I.E. Inc. Googledork: "powered by cms made simple" -=-=-=-=- - Summary: Optional user comment module not properly sanitized for <script> tags. -=-=-=-=- - PoC: Input the following into user comment form: <script type="text/javascript">alert('XSS')</script> -=-=-=-=-=-=-=-=-=- More information can be found at: http://www.l0j1k.com/security/CMSMadeSimple_1.0.2_25Dec06.txt -=-=-=-=-=-=-=-=-=- Merry Christmas everyone!
Current thread:
- XSS - CMS Made Simple v1.0.2 Curtis Zimmerman (Dec 26)
- <Possible follow-ups>
- Re: XSS - CMS Made Simple v1.0.2 nanoymaster (Dec 28)