========================================================= 70kft Design Multiple Vulnerabilities ========================================================= ######################################### # Name: 70kft Design Multiple Vulnerabilities # Date: 2010-05-23 # vendor: http://www.70kft.com # Author: Ashiyane Digital Security Team # Discovered By: XroGuE # Contact: Xrogue_p3rsi4n_hack3r[at]Hotmail[Dot]com # Home: www.Ashiyane.org ########################################## [+] XSS Injection Vulnerability: [+] Vulnerability: http://[site]/[path]/page.php?id=[XSS] [+] Live Demo: http://www.greatesttheft.com/lessonplan.php?id= ########################################### [+] HTML Injection Vulnerability: [+] Vulnerability: http://[site]/[path]/page.php?id=[HTML] [+] Live Demo: http://www.greatesttheft.com/lessonplan.php?id=XroGuE ########################################### _________________________________________________________________ Your E-mail and More On-the-Go. Get Windows Live Hotmail Free. https://signup.live.com/signup.aspx?id=60969