{"id":52,"date":"2026-04-07T16:13:20","date_gmt":"2026-04-07T16:13:20","guid":{"rendered":"https:\/\/qa-040726-3.sldev7.com\/?p=52"},"modified":"2026-04-07T16:13:20","modified_gmt":"2026-04-07T16:13:20","slug":"post-test_xss_and_sqli-php","status":"publish","type":"post","link":"https:\/\/qa-040726-3.sldev7.com\/?p=52","title":{"rendered":"Post .\/TEST_xss_and_sqli.php"},"content":{"rendered":"<p><html lang=\"en\"><br \/>\n<head><br \/>\n    <title>Target for XSS scan<\/title><br \/>\n<\/head><br \/>\n<body><\/p>\n<h1>XSS and SQL injections example:<\/h1>\n<p>URL example: <i>.\/TEST_xss_and_sqli.php?term=aaa&amp;id=1&amp;name=admin&amp;amount=20<\/i><\/p>\n<p>    <?php\n        require(\".\/wp-config.php\");\n\n        $conn = new mysqli(DB_HOST, DB_USER, DB_PASSWORD, DB_NAME);\n\n        if ($conn->connect_error) {<br \/>\n            die(&#8220;DB connection error: &#8221; . $conn->connect_error);<br \/>\n        }<\/p>\n<p>        $term = $_GET[&#8216;term&#8217;];<br \/>\n        if ($term) {<br \/>\n            echo &#8220;<\/p>\n<p>Parameter <code>term<\/code>: $term <\/p>\n<p>&#8220;;<br \/>\n        }<\/p>\n<p>        $number = $_GET[&#8216;id&#8217;];<br \/>\n        if ($number) {<br \/>\n            $result_number = $conn->query(&#8220;SELECT * FROM wp_users WHERE id=$number&#8221;);<br \/>\n            if ($result_number) {<br \/>\n                foreach($result_number as $raw){<br \/>\n                    foreach($raw as $val){<br \/>\n                        echo $val . &#8221; &#8220;;<br \/>\n                    }<br \/>\n                }<br \/>\n            } else {<br \/>\n                echo &#8220;<\/p>\n<p>Error: &#8221; . $conn->error . &#8220;<\/p>\n<p>&#8220;;<br \/>\n            }<br \/>\n        }<\/p>\n<p>        $string = $_GET[&#8216;name&#8217;];<br \/>\n        if ($number) {<br \/>\n            $result_string = $conn->query(&#8220;SELECT * FROM wp_users WHERE user_login= &#8216;$string&#8217; &#8220;);<br \/>\n            if ($result_string) {<br \/>\n                foreach($result_string as $raw){<br \/>\n                    foreach($raw as $val){<br \/>\n                        echo $val . &#8221; &#8220;;<br \/>\n                    }<br \/>\n                }<br \/>\n            } else {<br \/>\n                echo &#8220;<\/p>\n<p>Error: &#8221; . $conn->error . &#8220;<\/p>\n<p>&#8220;;<br \/>\n            }<br \/>\n        }<\/p>\n<p>        $conn->close();<br \/>\n    ?><\/p>\n<p>    <script>\n        const urlParams = new URLSearchParams(window.location.search);\n        const amount = urlParams.get('amount');<\/p>\n<p>        eval(amount);\n    <\/script><br \/>\n<\/body><br \/>\n<\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Target for XSS scan XSS and SQL injections example: URL example: .\/TEST_xss_and_sqli.php?term=aaa&amp;id=1&amp;name=admin&amp;amount=20<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-52","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts\/52","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=52"}],"version-history":[{"count":0,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=\/wp\/v2\/posts\/52\/revisions"}],"wp:attachment":[{"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=52"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=52"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qa-040726-3.sldev7.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=52"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}