Advisory: Active CMS 1.2.0 'mod' Cross-site Scripting Vulnerability Advisory ID: SSCHADV2011-020 Author: Stefan Schurtz Affected Software: Successfully tested on Active CMS 1.2.0 Vendor URL: http://www.activedev.net/ Vendor Status: informed CVE-ID: - ========================== Vulnerability Description: ========================== The backend of Active CMS 1.2.0 is prone to Cross-Site scripting vulnerability ================== Technical Details: ================== http:///activecms/admin/admin?action=module&mod=' ========= Solution: ========= - ==================== Disclosure Timeline: ==================== 28-Sep-2011 - informed developers 29-Sep-2011 - release date of this security advisory ======== Credits: ======== Vulnerabilities found and advisory written by Stefan Schurtz. =========== References: =========== http://www.activedev.net/ http://www.rul3z.de/advisories/SSCHADV2011-020.txt