first commit
This commit is contained in:
parent
985a5c928c
commit
f40a84879c
551 changed files with 72374 additions and 24 deletions
24
dvwa/vulnerabilities/xss_s/source/high.php
Normal file
24
dvwa/vulnerabilities/xss_s/source/high.php
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
<?php
|
||||
|
||||
if( isset( $_POST[ 'btnSign' ] ) ) {
|
||||
// Get input
|
||||
$message = trim( $_POST[ 'mtxMessage' ] );
|
||||
$name = trim( $_POST[ 'txtName' ] );
|
||||
|
||||
// Sanitize message input
|
||||
$message = strip_tags( addslashes( $message ) );
|
||||
$message = mysql_real_escape_string( $message );
|
||||
$message = htmlspecialchars( $message );
|
||||
|
||||
// Sanitize name input
|
||||
$name = preg_replace( '/<(.*)s(.*)c(.*)r(.*)i(.*)p(.*)t/i', '', $name );
|
||||
$name = mysql_real_escape_string( $name );
|
||||
|
||||
// Update database
|
||||
$query = "INSERT INTO guestbook ( comment, name ) VALUES ( '$message', '$name' );";
|
||||
$result = mysql_query( $query ) or die( '<pre>' . mysql_error() . '</pre>' );
|
||||
|
||||
//mysql_close();
|
||||
}
|
||||
|
||||
?>
|
||||
31
dvwa/vulnerabilities/xss_s/source/impossible.php
Normal file
31
dvwa/vulnerabilities/xss_s/source/impossible.php
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
<?php
|
||||
|
||||
if( isset( $_POST[ 'btnSign' ] ) ) {
|
||||
// Check Anti-CSRF token
|
||||
checkToken( $_REQUEST[ 'user_token' ], $_SESSION[ 'session_token' ], 'index.php' );
|
||||
|
||||
// Get input
|
||||
$message = trim( $_POST[ 'mtxMessage' ] );
|
||||
$name = trim( $_POST[ 'txtName' ] );
|
||||
|
||||
// Sanitize message input
|
||||
$message = stripslashes( $message );
|
||||
$message = mysql_real_escape_string( $message );
|
||||
$message = htmlspecialchars( $message );
|
||||
|
||||
// Sanitize name input
|
||||
$name = stripslashes( $name );
|
||||
$name = mysql_real_escape_string( $name );
|
||||
$name = htmlspecialchars( $name );
|
||||
|
||||
// Update database
|
||||
$data = $db->prepare( 'INSERT INTO guestbook ( comment, name ) VALUES ( :message, :name );' );
|
||||
$data->bindParam( ':message', $message, PDO::PARAM_STR );
|
||||
$data->bindParam( ':name', $name, PDO::PARAM_STR );
|
||||
$data->execute();
|
||||
}
|
||||
|
||||
// Generate Anti-CSRF token
|
||||
generateSessionToken();
|
||||
|
||||
?>
|
||||
22
dvwa/vulnerabilities/xss_s/source/low.php
Normal file
22
dvwa/vulnerabilities/xss_s/source/low.php
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
<?php
|
||||
|
||||
if( isset( $_POST[ 'btnSign' ] ) ) {
|
||||
// Get input
|
||||
$message = trim( $_POST[ 'mtxMessage' ] );
|
||||
$name = trim( $_POST[ 'txtName' ] );
|
||||
|
||||
// Sanitize message input
|
||||
$message = stripslashes( $message );
|
||||
$message = mysql_real_escape_string( $message );
|
||||
|
||||
// Sanitize name input
|
||||
$name = mysql_real_escape_string( $name );
|
||||
|
||||
// Update database
|
||||
$query = "INSERT INTO guestbook ( comment, name ) VALUES ( '$message', '$name' );";
|
||||
$result = mysql_query( $query ) or die( '<pre>' . mysql_error() . '</pre>' );
|
||||
|
||||
//mysql_close();
|
||||
}
|
||||
|
||||
?>
|
||||
24
dvwa/vulnerabilities/xss_s/source/medium.php
Normal file
24
dvwa/vulnerabilities/xss_s/source/medium.php
Normal file
|
|
@ -0,0 +1,24 @@
|
|||
<?php
|
||||
|
||||
if( isset( $_POST[ 'btnSign' ] ) ) {
|
||||
// Get input
|
||||
$message = trim( $_POST[ 'mtxMessage' ] );
|
||||
$name = trim( $_POST[ 'txtName' ] );
|
||||
|
||||
// Sanitize message input
|
||||
$message = strip_tags( addslashes( $message ) );
|
||||
$message = mysql_real_escape_string( $message );
|
||||
$message = htmlspecialchars( $message );
|
||||
|
||||
// Sanitize name input
|
||||
$name = str_replace( '<script>', '', $name );
|
||||
$name = mysql_real_escape_string( $name );
|
||||
|
||||
// Update database
|
||||
$query = "INSERT INTO guestbook ( comment, name ) VALUES ( '$message', '$name' );";
|
||||
$result = mysql_query( $query ) or die( '<pre>' . mysql_error() . '</pre>' );
|
||||
|
||||
//mysql_close();
|
||||
}
|
||||
|
||||
?>
|
||||
Loading…
Add table
Add a link
Reference in a new issue