======================================================================== | # Title : Exponent CMS versions 2.3.9 XSS vulnerability | # Author : indoushka | # email : indoushka4ever@gmail.com | # Tested on : windows 8.1 FranASSais V.(Pro) | # Version : 2.3.9 | # Vendor : https://sourceforge.net/projects/exponentcms/files/exponent-2.3.9.zip/download | # Dork : n/a ======================================================================== poc : This vulnerability affects :/source_selector.php. Attack details : URL encoded GET input time was set to 1485925200_947776'():;988077 The input is reflected inside