Hello Bugtraq! I want to warn you about Cross-Site Scripting and Insufficient Anti-automation vulnerabilities in IB Promotion Advanced Business Web Suite. It's Ukrainian commercial CMS. XSS (WASC-08): http://site/search/?qs=’;alert(document.cookie);// It's DOM Based XSS. Insufficient Anti-automation (WASC-21): http://site/register/ http://site/lostpasswd/ At these pages there is no protection from automated requests. Affected products: IB Promotion Advanced Business Web Suite v1.0, IB Pro CMS v1.0 and IB Pro CMS v2.0. IB Promotion Advanced Business Web Suite - it's previous name of system IB Pro CMS. Timeline: 2010.06.22 - informed admin of the site, where I found vulnerabilities. 2010.06.23 - announced at my site. 2010.06.24 - informed developers of CMS. 2010.09.09 - disclosed at my site. Both admin of vulnerable site and developers (in their engine and at their own site) didn't fix the holes. I mentioned about these vulnerabilities at my site (http://websecurity.com.ua/4313/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua