TUCoPS :: Web :: PHP :: b06-3581.htm

Orbitmatrix PHP Script v1.0
Orbitmatrix PHP Script v1.0
Orbitmatrix PHP Script v1.0



Orbitmatrix PHP Script v1.0=0D
=0D
Homepage:=0D
http://www.orbitcoders.com/=0D 
=0D
Affected files:=0D
index.php=0D
=0D
Possible SQL injection?:=0D
http://www.example.com/index.php?page_name='=0D 
=0D
And by trying a XSS vuln as shown below on page_name we see the query below which is displayed on screen:=0D
=0D
http://www.example.com/index.php?page_name=contact