source: https://www.securityfocus.com/bid/25008/info Asp cvmatik is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible. Asp cvmatik 1.1 is vulnerable. 1-http://www.example.com/cv.asp You write xss code in page's text box Adý or Soyadý or Ehliyet or Askerlik or GSM etc... Press to "tamam"(ok) button. 2-next page