source: https://www.securityfocus.com/bid/46383/info Wikipad is prone to a cross-site scripting vulnerability, an HTML-injection vulnerability, and an information-disclosure vulnerability. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, and obtain sensitive information. Wikipad 1.6.0 is vulnerable; other versions may also be affected. Information-disclosure: http://www.example.com/pages.php?id=./../../../../../txt_file Cross-site scripting: http://www.example.com/pages.php?id=index"> http://www.example.com/pages.php?action=edit&id=27-01-2011"> HTML-injection: