Hacker News new | ask | show | jobs
by 6510 661 days ago
I was just fixing some php from 2001 and it allows visitors to execute php, inject js, read/write the database, send emails, extract md5 passwords, extract email addresses.

I'm surprised things worked out so well.