===================================================== Social Engine 4 Persistent XSS & Non-Persistent XSS ===================================================== :----------------------------------------------------------------------------------------------------------------------------------------: : # Exploit Title : Social Engine 4 Persistent XSS & Non-Persistent XSS : # Date : 27 July 2012 : # Author : X-Cisadane : # Software Link : http://www.socialengine.com/buy-social-engine : # Version : ALL : # Category : Web Applications : # Vulnerability : Persistent & Non-Persistent XSS : # Tested On : Mozilla Firefox 7.0.1 (Windows) : # Greetz to : X-Code, Borneo Crew, Depok Cyber, Explore Crew, CodeNesia, Bogor-H, Jakarta Anonymous Club, Winda Utari :----------------------------------------------------------------------------------------------------------------------------------------: DORKS ===== "This will be the end of your profile link, for example:" OR intext:"This page will contain the privacy statement of your choice." XSS CODE =======