source: https://www.securityfocus.com/bid/37564/info DieselPay is prone to a cross-site scripting vulnerability and a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input. An attacker could exploit these vulnerabilities to obtain sensitive information, execute arbitrary script code, or steal cookie-based authentication credentials. DieselPay 1.6 is vulnerable; other versions may also be affected. The following example URIs are available: http://www.example.com/dieselpay/index.php?read=alert(213771818860)%3B http://www.example.com/dieselpay/index.php?read=../../../../../../../../boot.ini