A persistent cross-site scripting vulnerability in Newscoop version 3.5.1 can be exploited to execute arbitrary JavaScript.
f66ea8bdd11017391ef795c8f21de5f5781df107aaf04457c4e878c65eb1b2b6
------------------------------------------------------------------------
Software................Newscoop 3.5.1
Vulnerability...........Persistent Cross-site Scripting
Threat Level............Moderate (2/5)
Download................http://www.sourcefabric.org/en/products/newscoop_overview/
Vendor Contact Date.....3/10/2011
Disclosure Date.........3/24/2011
Tested On...............Windows Vista + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
Email...................John Leitch <john@autosectools.com>
------------------------------------------------------------------------
--Description--
A persistent cross-site scripting vulnerability in Newscoop 3.5.1 can
be exploited to execute arbitrary JavaScript.
--PoC--
Enter the following in the Comment field of any article:
</textarea><script>alert(0)</script>
Navigate to the comment approval section of the admin page to see the result.