================= IUT-CERT ================= Title: YEKTAWEB CMS XSS Vulnerability Vendor: www.yektaweb.com Dork: Powered by Academic Web Tools ( AWT ) - Yektaweb Collection Type: Input.Validation.Vulnerability (cross-Site scripting) Fix: N/A ================== nsec.ir ================= Description: -------------------------------------------- YEKTAWEB is an Academic web tool. "browse.php" pages in this CMS is vulnerable to xss and link injection. Vulnerability Variant: --------------------------------------------- XSS: "browse.php" in "a_code" parameter. http://www.example.com/browse.php?a_code=">&sid=1&slc_lang=fa http://www.example.com/browse.php?a_code=1. http://www.example.com/browse.php?a_code=1>">. Solution: --------------------------------------------- Input validation of Parameter "a_code" should be corrected. Credit: --------------------------------------------- Isfahan University of Technology - Computer Emergency Response Team Thanks to : N. Fathi, M. R. Faghani