------------------------------------------------------------------------ Software................Newscoop 3.5.1 Vulnerability...........Persistent Cross-site Scripting Threat Level............Moderate (2/5) Download................http://www.sourcefabric.org/en/products/newscoop_overview/ Vendor Contact Date.....3/10/2011 Disclosure Date.........3/24/2011 Tested On...............Windows Vista + XAMPP ------------------------------------------------------------------------ Author..................AutoSec Tools Site....................http://www.autosectools.com/ Email...................John Leitch ------------------------------------------------------------------------ --Description-- A persistent cross-site scripting vulnerability in Newscoop 3.5.1 can be exploited to execute arbitrary JavaScript. --PoC-- Enter the following in the Comment field of any article: Navigate to the comment approval section of the admin page to see the result.