On Tue, Sep 28, 2010 at 08:23:19PM +0200, Yam Mesicka wrote: > My name is Yam Mesicka, I'm from Israel and this is my first big > disclosure (so help needed is here :-) > I found XSS on phpMyFAQ system, versions 2.6.6 to 2.6.8. > > Dork: intitle:"Powered By phpMyFAQ 2.6.8" > XSS: site-location/index.php/"><script>alert("XSS")</script> > Vul: 2.6.6 <= phpMyFAQ <= 2.6.8 > > The problem has been fixed on phpMyFAQ 2.6.9. > > Advisory here: http://www.phpmyfaq.de/advisory_2010-09-28.php > > If more details are needed, please contact me. > - Yam Mesicka > - Israel > - www.mesicka.com This issue can be refered as CVE-2010-4821. - Henri Salo