# Exploit Title: Simple Forum PHP (XSS/HTML Injection Vulnerabilities) # Date: August 25, 2010 # Author: arnab_s # Software Link: http://www.simpleforumphp.com/forum/admin.php?act=topic_options # Price: $24.99 found bug on: http://server/demo_guestbook.php?act=new details: you can insert html/javascript codes. works if Approval option on http://www.simpleforumphp.com/demo_forum.php act=topic_options were not checked.