first commit
This commit is contained in:
parent
985a5c928c
commit
f40a84879c
551 changed files with 72374 additions and 24 deletions
31
dvwa/vulnerabilities/xss_s/source/impossible.php
Normal file
31
dvwa/vulnerabilities/xss_s/source/impossible.php
Normal file
|
|
@ -0,0 +1,31 @@
|
|||
<?php
|
||||
|
||||
if( isset( $_POST[ 'btnSign' ] ) ) {
|
||||
// Check Anti-CSRF token
|
||||
checkToken( $_REQUEST[ 'user_token' ], $_SESSION[ 'session_token' ], 'index.php' );
|
||||
|
||||
// Get input
|
||||
$message = trim( $_POST[ 'mtxMessage' ] );
|
||||
$name = trim( $_POST[ 'txtName' ] );
|
||||
|
||||
// Sanitize message input
|
||||
$message = stripslashes( $message );
|
||||
$message = mysql_real_escape_string( $message );
|
||||
$message = htmlspecialchars( $message );
|
||||
|
||||
// Sanitize name input
|
||||
$name = stripslashes( $name );
|
||||
$name = mysql_real_escape_string( $name );
|
||||
$name = htmlspecialchars( $name );
|
||||
|
||||
// Update database
|
||||
$data = $db->prepare( 'INSERT INTO guestbook ( comment, name ) VALUES ( :message, :name );' );
|
||||
$data->bindParam( ':message', $message, PDO::PARAM_STR );
|
||||
$data->bindParam( ':name', $name, PDO::PARAM_STR );
|
||||
$data->execute();
|
||||
}
|
||||
|
||||
// Generate Anti-CSRF token
|
||||
generateSessionToken();
|
||||
|
||||
?>
|
||||
Loading…
Add table
Add a link
Reference in a new issue