TUCoPS :: Web :: CMS / Portals :: c07-1696.htm

Fix & Chips CMS v1.0
Vulnerable files:


staff.php XSS
User input in the Announcement box isn't properly sanatized before being generated.

A few PoC's that work:



delete-announce.php XSS 


User input in all of the input boxes when adding a new customer isnt sanatized. For a PoC in any input box when adding a new 

client put:


Because of the above, all malicious user input that is listed on the pages search.php and client-results.php will execute as well.


- Luny

