Did anyone find any interesting sites with this vulnerability? I found a Chinese exchange program and an 'ask Army' *.mil site that has since been patched.
I found that army site too, though I didn't find anything interesting there. I found a Sony site. Some .edu's. Most everything I found seemed to have the exact same source code.
That's strange. I forgot about the Sony site. The best one was the Exchange program. Was cool to see a connectdb.php file with 3 credentials to 3 different servers...
Comments
Did anyone find any interesting sites with this vulnerability? I found a Chinese exchange program and an 'ask Army' *.mil site that has since been patched.
I found that army site too, though I didn't find anything interesting there. I found a Sony site. Some .edu's. Most everything I found seemed to have the exact same source code.
That's strange. I forgot about the Sony site. The best one was the Exchange program. Was cool to see a connectdb.php file with 3 credentials to 3 different servers...
http://ssa-custhelp.ssa.gov/cgi-bin/ssa.cfg/php/enduser/std_...
https://help.us.army.mil/cgi-bin/akohd.cfg/php/enduser/std_a...
https://help.auctions.overstock.com/app/answers/detail/a_id/...
http://askus.columbia.edu/app/answers/list/p/0/kw/student%20...
http://help.station.sony.com/app/answers/detail/a_id/10404?-...
http://nam-en.apc.com/cgi-bin/nam_en.cfg/php/enduser/std_adp...
http://help.linkedin.com/cgi-bin/linkedin.cfg/php/enduser/st...
http://askdrs.ct.gov/Scripts/drsrightnow.cfg/php.exe/enduser...
http://askfsis.custhelp.com/app/answers/detail/a_id/1249?-s
http://linksys.custhelp.com/cgi-bin/linksys.cfg/php/enduser/...
http://ubisoft.custhelp.com/cgi-bin/ubisoft.cfg/php/enduser/...
https://ebay.custhelp.com/cgi-bin/ebay.cfg/php/enduser/std_a...