Some monday morning fun: SANS content management system fails to properly sanitize user inputs, allowing for injection of malicious web script or HTML. Prior authentication is required, limiting this issue to blog posts by people with malicious intentions or who don't know what they're doing. POC here: http://isc.sans.org/diary.html?storyid=4565 Search the source code for 'adsitelo' (without quotes). _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/