
|
NOTE: NO LONGER APPLICABLE DUE TO NEW WEBSITE.
Southern Railway are a train operator in the UK. Possible SQL Injection vunerability:
http://www.southernrailway.com/live_running.php?crs=
I stuck a ' in the crs parameter, and I got an error, including a nice run down/debug of the SQL statement. In the process, it also opened up the possible chance of an XSS vulnerability, although it seems they have entitised the variable. Still possible to insert your own error message to trick someone into visiting a naughty website.
http://www.southernrailway.com/error500.php?REDIRECT_ERROR_NOTES=Hello
Click here =D No responsibility taken for this information |
Online SoundCloud Downloader, NEW!Download tracks posted on SoundCloud for free in high-quality MP3! SoundScrape.netUseful eBay Links |