<?php
// This code is vulnerable when cmd == 1 and text contains a script
// ?cmd=1&text=%3Cscript%3Ewindow.location%20=%20%22http://www.google.com/%22%3C/script%3E
function get($c){
if ($c == 1) return $_GET['text'];
else return htmlspecialchars($_GET['text']);
}
$cmd = (int) $_GET["cmd"];
if ($cmd == 0) echo "0";
else echo ($cmd . " " . get($cmd));
?>
- Output for 8.0.0 - 8.0.30, 8.1.0 - 8.1.28, 8.2.0 - 8.2.18, 8.3.0 - 8.3.6
- Warning: Undefined array key "cmd" in /in/oVU3U on line 10
0
- Output for 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38, 5.6.0 - 5.6.28, 7.0.0 - 7.0.20, 7.1.0 - 7.1.20, 7.2.0 - 7.2.33, 7.3.12 - 7.3.31, 7.4.0 - 7.4.33
- Notice: Undefined index: cmd in /in/oVU3U on line 10
0
- Output for 7.3.32 - 7.3.33
- 0
- Output for 4.3.0 - 4.3.11, 4.4.0 - 4.4.9, 5.0.0 - 5.0.5, 5.1.0 - 5.1.6, 5.2.0 - 5.2.17
- Notice: Undefined index: cmd in /in/oVU3U on line 10
0
preferences:
234.32 ms | 402 KiB | 355 Q