Jump to content

Any security risks? loopholes?


tommyda

Recommended Posts

Cross Site Scripting(XSS):

You can submit ">code when you register and and it will execute after you login.

 

Cross Site Scripting(XSS):

http://websiteconstructionteam.com/phptesting/mobile-social-networking/profile.php?user="><marquee><h1>test

 

Full Path Disclosure:

http://websiteconstructionteam.com/phptesting/mobile-social-networking/newblog.php

Warning: Cannot modify header information - headers already sent by (output started at /home/website/public_html/phptesting/mobile-social-networking/newblog.php:13) in /home/website/public_html/phptesting/mobile-social-networking/newblog.php on line 58

 

Full Path Disclosure:

http://websiteconstructionteam.com/phptesting/mobile-social-networking/newmsg.php?to=

Warning: Cannot modify header information - headers already sent by (output started at /home/website/public_html/phptesting/mobile-social-networking/config.php:2) in /home/website/public_html/phptesting/mobile-social-networking/newmsg.php on line 37

 

Full Path Disclosure:

http://websiteconstructionteam.com/phptesting/mobile-social-networking/inbox.php

Warning: Cannot modify header information - headers already sent by (output started at /home/website/public_html/phptesting/mobile-social-networking/config.php:2) in /home/website/public_html/phptesting/mobile-social-networking/inbox.php on line 41
Link to comment
Share on other sites

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.