Title: RunCMS XSS Vulnerability via User Agent Vendor: RunCMS Product: RunCMS Tested Version: 2.1 Threat Class: XSS Severity: Medium Remote: yes Local: no Discovered By: Andrei Rimsa Alvares ===== Description ===== RunCMS is prone to a XSS vulnerability by mangling the user-agent field on a http request to a script within the forum module. ----- modules/forum/check.php ----- 01: window.alert('XSS');" http://target/modules/forum/check.php ===== Workaround ===== Remove the affected file form the system: modules/forum/check.php. ===== Disclosure Timeline ===== June, 16 2010 - Vendor notification. June, 17 2010 - Vendor response confirming the bug. July, 07 2010 - Public disclosure. ===== References ===== http://www.runcms.org