# Exploit Title: Permanent XSS and Html Code Injection in the Fofou Forums # Google Dork: intext:Powered by fofou # Date: 15.08.2011 # Author: Sony # Software Link: http://blog.kowalczyk.info/software/fofou/index.html # Version: all version .............................. ....................................................................... http://www.server/forum/post New Topic: (all fields) XSS: