From 7659ccb2a755de3a9efa60a2b86f35c35a265475 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 20 Jul 2023 19:04:18 +0100 Subject: [PATCH] Making xss Pages 2-8 Vulnerable to XSS_stored and reflected --- XSS/index.php | 20 +++- XSS/page2.php | 205 +++++++++++++++++++++++++++++++++++++++ XSS/page3.php | 205 +++++++++++++++++++++++++++++++++++++++ XSS/page4.php | 205 +++++++++++++++++++++++++++++++++++++++ XSS/page5.php | 205 +++++++++++++++++++++++++++++++++++++++ XSS/page6.php | 257 +++++++++++++++++++++++++++++++++++++++++++++++++ XSS/page7.php | 258 ++++++++++++++++++++++++++++++++++++++++++++++++++ XSS/page8.php | 258 ++++++++++++++++++++++++++++++++++++++++++++++++++ 8 files changed, 1611 insertions(+), 2 deletions(-) create mode 100644 XSS/page2.php create mode 100644 XSS/page3.php create mode 100644 XSS/page4.php create mode 100644 XSS/page5.php create mode 100644 XSS/page6.php create mode 100644 XSS/page7.php create mode 100644 XSS/page8.php diff --git a/XSS/index.php b/XSS/index.php index 05ed52c..f1507fa 100644 --- a/XSS/index.php +++ b/XSS/index.php @@ -155,11 +155,27 @@ - - +setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); + $conn->exec("USE OSTE"); + $sql = "DELETE FROM comontair"; + $stmt = $conn->prepare($sql); + $stmt->execute(); +} catch (PDOException $e) { + echo "Connection failed: " . $e->getMessage(); +} + +?> diff --git a/XSS/page2.php b/XSS/page2.php new file mode 100644 index 0000000..3015c20 --- /dev/null +++ b/XSS/page2.php @@ -0,0 +1,205 @@ + + + + + + OSTE Vulnerable Web Application + + + +
+ Logo + back + + +
+ +

Greetings, What's your name?

+
+
+ + + +
+
+Welcome To OSTE Vulnerable web application <3"; +$name = str_replace( '