http://www.example.com/member.php?action=viewpro&member=[XSS] http://www.example.com/portfolio.php?cat_id=[XSS] http://www.example.com/portfolio_photo_popup.php?id=[XSS]