Guest User

Untitled

a guest
Jul 22nd, 2018
71
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 0.46 KB | None | 0 0
  1. <?php
  2.   /* DevBug - PHP Static Code Analysis written (mostly) in JavaScript */
  3.  
  4.   // Cross-Site Scripting (XSS)
  5.   $name = $_GET['name']; // tainted by user input
  6.   $a .= $name;
  7.  
  8.   echo('Hello ' . $name); # tainted data reaches sensitive sink
  9.  echo($a);
  10.   echo("" . $name);
  11.  
  12.  
  13.   // SQL Injection
  14.   $id = $_POST['id'];
  15.   $b .= $id;
  16.   mysql_query("SELECT user FROM users WHERE id = " . $id);
  17.   mysql_query("SELECT user FROM users WHERE id = " . $b);
  18.  
  19. ?>
Add Comment
Please, Sign In to add comment