SQL Injection: Found on http://www.example.com/formulasi/kelas-siswa.html parameter : kelas post data : kelas=1{SQL_HERE} Cross-site scripting: Found On parameter : tgl http://www.example.com/cmsformulasi/index.php?p=tglberita&tgl= Cross-site request forgery: