mAds v1.0 Homepage: http://lowpricescripts.com/product_info.php?products_id=51 Affected files: *Searching ----------------------------------- XSS vuln when searching: Like the hotbot XSS vuln, when searching mAds returns with its results they are generated dynamically on screen, with no filtering at all. For a PoC as your search string put in: Screenshots: http://www.youfucktard.com/xsp/mads1.jpg Im sure other vulnerabilities aside from XSS could be also possible due to this. ------------------------------------