# Exploit Title: glfusion CMS 1.2.1 stored XSS via img tag # Date: 14-1-2010 # Author: Saif El-Sherei # Software Link: www.glfusion.org/filemgmt/viewcat.php?cid=1 # Version: 1.2.1 # Tested on: Firefox 3.0.15 Info: * glFusion * gives you the ability to easily create websites and online communities complete with add-ons like Forums, CAPTCHA/Spam filters, Calendars, File & Media Gallery management solutions, WYSIWYG editors, and MooTools AJAX support, all right out of the box. Details: Failure to sanitize the BBcode image tags in the forum posts allows attacker to perform XSS attacks. also noted that u can't inject any "src" attribute in the attack so we use the second POC. POC: [img w=30> h=30]images/help.png[/img] [img w=30> h=30]x[/img] Regards, Saif El-Sherei OSCP