| Title |
CMS Made Simple SearchInput Cross-Site Scripting Vulnerability |
| Published |
2006-12-11-12:00AM |
| Updated |
2007-01-25-04:19PM |
| Class |
Input Validation Error |
| CVE |
|
| Remote |
Yes |
| Local |
No |
| Credit |
Nicokiller and NanoyMaster are credited with the discovery of this vulnerability. |
| Vulnerable |
CMS Made Simple CMS Made Simple 1.0.2
CMS Made Simple CMS Made Simple 0.10.2 |
| Not Vulnerable |
CMS Made Simple CMS Made Simple 1.0.3 |
| Code |
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept URI is available:
/data/vulnerabilities/exploits/21527.html
|
| TXT |
 |