AEF version 1.0.8 suffers from a cross site scripting vulnerability.
d42c5711ebe70de5d5ae838aaac8eb94bda8740e2ebcdedd8b1a91850c9b4241
Dear Sir / Madam
The Itsecteam has discovered a new bug in AEF Version 1.0.8 CMS and will be glad to report and public it .
* more information about this bug is listed below :
Topic : AEF Version 1.0.8
Bug Type : Cross Site Scripting
Credit : ItSecTeam
Remote : Yes
Status : Bug
Download Link :https://www.anelectron.com/downloads/
# mail : Bug@ItSecTeam.com
# Dork : Powered By AEF Version 1.0.8
#Special Tnx : Amin Shokohi(Pejvak), 0xd41684c654 , r3dmove And All It Security Team Members
#Website : WwW.ItSecTeam.com<https://www.itsecteam.com/>
########################## Exploit #############################
https://Site.Com/AEF/index.php?act=calendar&date=Xss