Jump to content

Recommended Posts

XSS unencode warning:

The unencoded attack string was found in the html of the document. Other browsers may be vulnerable to this XSS string.

Tested value: ¼script¾document.vulnerable=true;¼/script¾



XSS unencode warning:

The unencoded attack string was found in the html of the document. Other browsers may be vulnerable to this XSS string.

Tested value: ¼script¾document.vulnerable=true;¼/script¾




The XSS is that only on the change password or on the whole script?

i dont remember now i should have been more specific ill go rescan :-\


Notice: Use of undefined constant username - assumed 'username' in E:\xampp\htdocs\meeting-plaza.eu\test\test\register.php on line 162


Notice: Use of undefined constant username - assumed 'username' in E:\xampp\htdocs\meeting-plaza.eu\test\test\register.php on line 178

rescanned that exploit was on editprofile.php i cant be specific as ot what variable  ;)


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN" "http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">

<meta http-equiv="content-type" content="text/html; charset=UTF-8"/>
<meta name="description" content="Exxelent is a online dealer game host where you can start your own dealer game"/>
<meta name="keywords" content="exxelent, dealer, game, gratis, free, win, paid"/> 
<meta name="author" content="chrissie"/> 
<link rel="stylesheet" type="text/css" href="default.css" media="screen"/>
<title><? echo"$sitename"; ?></title>


<div class="outer-container">

<div class="inner-container">

<div class="header">

	<div class="title">

		<span class="sitename"><a href="index.php"><? echo"$sitename"; ?></a></span>
		<div class="slogan">Your Own DealerGame</div>



<div class="path">

		<a href="index.php">Home</a> &#8250; <a href="register.php">Aanmelden</a> &#8250; <a href="login.php">Login</a>


<div class="main">		

	<div class="content">

        <h1>Profiel wijzigen</h1>
        <div class="descr"></div>
        <p>Hier kun je je eigen profiel aanpassen en dat van je game<br /></p>
if (isset($logged['id'])) { 
if (isset($_POST['submit'])) {
$email = isset($_POST['email'])?addslashes(htmlspecialchars($_POST['email'])):"";
$location = isset($_POST['location'])?addslashes(htmlspecialchars($_POST['location'])):"";
$dername = isset($_POST['dername'])?addslashes(htmlspecialchars($_POST['dername'])):"";
$welcomet = isset($_POST['welcomet'])?addslashes(htmlspecialchars($_POST['welcomet'])):"";
//updates there profile in the db 
$update = mysql_query("UPDATE `members` SET `email` = '$email', `welcomet` = '$welcomet', `dername` = '$dername', `location` = '$location' WHERE `username` = '$logged[username]'") or die(mysql_error());
echo "Profiel is geupdate!"; 
$getuser = mysql_query("SELECT * FROM `members` WHERE `username` = '$logged[username]'") or die(mysql_error());
$user = mysql_fetch_array($getuser); 
echo "<form action='editprofile.php?update' method='post'> 
Email: <input type='text' name='email' size='30' maxlength='55' value='$user[email]'><br>
Land: <input type='text' name='location' size='30' maxlength='40' value='$user[location]'><br>
dealernaam: <input type='text' name='dername' size='30' maxlength='40' value='$user[welcomet]'><br>
Welkoms tekst: <input type='text' name='welcomet' size='90' maxlength='240' value='$user[dername]'><br>
<input type='submit' value='Update' name='submit'> 
echo "Je bent niet ingelogd."; 

	<div class="navigation">

			<li><a href="index.php">index</a></li>
			<li><a href="register.php">aanmelden</a></li>
if(isset($logged['id'])) {
//Logged in code
          			echo "<li><a href=\"login.php\">login</a></li>";
			<li><a href="members.php">leden</a></li>


	<div class="navigation">
if(isset($logged['id'])) {
			<li><a href=\"editprofile.php\">Wijzig profiel</a></li>
			<li><a href=\"changepass.php\">Verander wachtwoord</a></li>
			<li><a href=\"logout.php\">Uitloggen</a></li>

	<div class="clearer"> </div>


<div class="footer">

	<span class="left">
		© 2008 <a href="index.php">exxelent.nl</a> Valid <a href="http://jigsaw.w3.org/css-validator/check/referer">CSS</a>

	<span class="right">Design by <a href="http://arcsin.se/">Arcsin</a> <a href="http://templates.arcsin.se/">Web Templates</a></span>

	<div class="clearer"></div>






  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.