# Ariko-Security: Security Audits , Audyt bezpieczestwa
# Advisory: 3/2/2012

# CVE-2008-4648

============ { Ariko-Security - Advisory #3/2/2012 } =============

Elxis CMS Cross-site scripting (XSS)

Vendor's description of software and download:
# http://www.elxis.org

Dork:
# N/a

Application Info:
# elxis 2009.3 aphrodite / february 2012

Vulnerability Info:
# Type: XSS

Time Table:
# 13/02/2012 - Vendor notified

XSS:
#Input passed to the "i" parameter in /includes/simplepie/handler_image.php is not properly sanitised before being returned to the user.

Solution:
# Input validation of vulnerable parameters should be corrected.

POC:

http://www.elxis-demo.com/includes/simplepie/handler_image.php?i=db222055fb39%3CsCrIpT%3Ealert%281234%29%3C%2fsCrIpT%3E

Credit:
# Discoverd By: Maciej Gojny / Ariko-Security 2012
Our advisory:
http://advisories.ariko-security.com/2012/audyt_bezpieczenstwa_3m2.html