source: https://www.securityfocus.com/bid/45432/info BLOG:CMS is prone to a cross-site-scripting vulnerability and multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content. Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible. BLOG:CMS 4.2.1.e is vulnerable; prior versions may also be affected. Cross Site Scripting POCs:
http://www.example.com/admin/index.php?action=settingsedit">