SiteKiosk versions below 6.5.150 suffer from a validation input flaw that allows for cross site scripting and arbitrary filesystem access.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/53046/sitekiosk-xss.txt
Source: https://packetstormsecurity.com/files/53046/sitekiosk-xss.txt.html

