A reflected cross site scripting vulnerability in V-CMS version 1.0 can be exploited to execute arbitrary JavaScript.
c6bd8d414c203e4d7061c79f3542c1b5b217553d5e43319d293458513d863d05
------------------------------------------------------------------------
Software................V-CMS 1.0
Vulnerability...........Reflected Cross-site Scripting
Threat Level............Low (1/5)
Download................http://v-cms.org/
Discovery Date..........11/13/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in V-CMS 1.0 can be
exploited to execute arbitrary JavaScript.
--PoC--
/v-cms/redirect.php?p=[XSS]
/v-cms/includes/TrueColorPicker/index.php?preload=&df=&box=[XSS]