lostid.php input data isn't properally sanatized & filtered which allows
for XSS
example:
put in box: <script>alert('hi')</script>
Input data on join.php isn't sanatized and can create mysql errors if users
input malicious data.
example:
You have an error in your SQL syntax; check the manual that corresponds to
your MySQL server version for the right
syntax to use near
'hi'','9cdfb439c7876e703e307864c9167a15','0','19052006','-')' at line 2
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.