Product: CMS Made Simple v1.0.2 Class: XSS Website: http://www.cmsmadesimple.org Found by: L0j1k of D.I.E. Inc. Googledork: "powered by cms made simple" -=-=-=-=- - Summary: Optional user comment module not properly sanitized for <script> tags. -=-=-=-=- - PoC: Input the following into user comment form: <script type="text/javascript">alert('XSS')</script> -=-=-=-=-=-=-=-=-=- More information can be found at: http://www.l0j1k.com/security/CMSMadeSimple_1.0.2_25Dec06.txt -=-=-=-=-=-=-=-=-=- Merry Christmas everyone!