Full title: OrderSys 1.6.4 Cross Site Scripting / SQL Injection Vulnerabilities Category: web applications Platform: php # 0day.today @ http://0day.today/