ProNews V1.5 -------------------- Vendor site: http://www.scripthp.com/ Product: ProNews V1.5 Vulnerability: XSS & SQL Injection Vulnerability Credits: Mr_KaLiMaN Reported to Vendor: 01.12.06 Public disclosure: 09.12.06 Description: ------------ XSS permanent: http://[victim]/[script_news_path]/admin/change.php?pseudo=[XSS]&email=">[XSS]&date=[XSS]&sujet=[XSS]&message=[XSS]&site=">[XSS]