|
New Advisory:=0D
Snewscms Rus v2=0D
http://www.medprostuda.ru=0D
=0D
--------------------Summary----------------=0D
Software: SnewsCMS Rus v. 2.3=0D
Sowtware's Web Site: http://www.snewscms.net.ru=0D
Versions: 2.4=0D
Critical Level: Moderate=0D
Type: XSS=0D
Class: Remote=0D
Status: Unpatched=0D
PoC/Exploit: Not Available=0D
Solution: Not Available=0D
Discovered by: http://medprostuda.ru=0D
=0D
-----------------Description---------------=0D
1. XSS.=0D
=0D
Vulnerable script: search.php=0D
=0D
Parameters 'query' is not=0D
properly sanitized before being used in HTML tags.
XSS
=0D">http://target.com/search.php?query=">XSS
=0D
=0D
--------------PoC/Exploit----------------------=0D
Waiting for developer(s) reply.=0D
=0D
--------------Solution---------------------=0D
No Patch available.=0D
=0D
--------------Credit-----------------------=0D
Discovered by: http://www.medprostuda.ru=0D
http://www.eserg.ru