WBNews versions less than v1.1.0 suffer from XSS in the "Name" field.
a7d634df5d3ff9ee3fdb71d0c60caf740f9c3f1c27fc816bd857c6811b9fed55
it is possible to be executed I cosay arbitrary within the system wbnews in the field "Name" for example <script>alert("Hello DragoN");</script>
WBNews
http://www.webmobo.com/
DragoN
DragonJAR@gmail.com