23 lines
		
	
	
		
			417 B
		
	
	
	
		
			PHP
		
	
	
	
	
	
			
		
		
	
	
			23 lines
		
	
	
		
			417 B
		
	
	
	
		
			PHP
		
	
	
	
	
	
| <!DOCTYPE html>
 | |
| <html>
 | |
| <head>
 | |
| 	<title>XSS 4</title>
 | |
| </head>
 | |
| <body>
 | |
| <form method="GET" action="" name="form">
 | |
|    <p>Your name:<input type="text" name="username"></p>
 | |
|    <input type="submit" name="submit" value="Submit">
 | |
| </form>
 | |
| <?php 
 | |
| if (isset($_GET["username"])) {
 | |
|     $values = array("script", "prompt", "alert", "h1");
 | |
| 
 | |
|  	$user = str_replace($values, " ",$_GET["username"]);
 | |
| 	echo "$user";
 | |
| }
 | |
| 
 | |
|  ?>
 | |
| 
 | |
| </body>
 | |
| </html>
 | 
