phpinfo() Posted February 8, 2008 Share Posted February 8, 2008 http://www.rovexchange.com/wc_maritime_employment.php Any issues with our site. Specifically with the database login - exploits, injections, errors etc. Thanks! Link to comment https://forums.phpfreaks.com/topic/90129-site-login-exploits-errors/ Share on other sites More sharing options...
agentsteal Posted February 9, 2008 Share Posted February 9, 2008 Array: http://www.rovexchange.com/mc_company_listings.php?q[] Array: http://www.rovexchange.com/mc_eqpt_for_sale.php?equipment_categ=a&q[] Array: http://www.rovexchange.com/mc_company_listings.php?business_categ[] Array: http://www.rovexchange.com/mc_eqpt_for_sale.php?equipment_categ[] Array: http://www.rovexchange.com/mc_eqpt_for_sale.php?q[] Array: http://www.rovexchange.com/mc_company_listings.php?business_categ=a&q[] Cross Site Scripting: http://www.rovexchange.com/mc_company_listings.php?business_categ=<marquee><h1>vulnerable</marquee> Cross Site Scripting: http://www.rovexchange.com/mc_eqpt_for_sale.php?equipment_categ=<marquee><h1>vulnerable</marquee> Cross Site Scripting: There is Cross Site Scripting when you log in if your password contains ">code. Cross Site Scripting: There is Cross Site Scripting when you log in if your username contains ">code. Cross Site Scripting: There is Cross Site Scripting on https://www.rovexchange.com/signup_add_company.php if the fields contain ">code. Cross Site Scripting: http://www.rovexchange.com/mc_company_listings.php?q="><marquee><h1>vulnerable</marquee> Cross Site Scripting: http://www.rovexchange.com/mc_company_listings.php?business_categ=a&q=<marquee><h1>vulnerable</marquee> Cross Site Scripting: http://www.rovexchange.com/mc_eqpt_for_sale.php?equipment_categ=a&q=<marquee><h1>vulnerable</marquee> SQL Error: http://www.rovexchange.com/mc_company_listings.php?q=a&business_categ=' SQL Error: http://www.rovexchange.com/mc_eqpt_for_sale.php?q=a&equipment_categ=' Link to comment https://forums.phpfreaks.com/topic/90129-site-login-exploits-errors/#findComment-462239 Share on other sites More sharing options...
Coreye Posted February 9, 2008 Share Posted February 9, 2008 Cross Site Scripting: http://www.rovexchange.com/forgotpasswd.php There is Cross Site Scripting if you enter a username that contains ">code. Link to comment https://forums.phpfreaks.com/topic/90129-site-login-exploits-errors/#findComment-462518 Share on other sites More sharing options...
Recommended Posts