-
Notifications
You must be signed in to change notification settings - Fork 5
/
Copy pathxss_reflected_json.php
91 lines (64 loc) · 2.25 KB
/
xss_reflected_json.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
<?php include_once "includer.php";
function checkInput($data)
{
switch($_COOKIE['security_level'])
{
case "0" :
$data = no_check($data);
break;
case "1" :
$data = xss_check_3($data);
break;
case "2" :
$data = xss_check_3($data);
break;
default :
$data = no_check($data);
break;
}
return $data;
}
?>
<div class="container">
<h1>XSS(Cross Site Script) - Reflected (JSON)</h1>
<!--<a href="#">okan <script>alert(1)</script> </a>-->
<form action="<?php echo($_SERVER["SCRIPT_NAME"]);?>" method="POST">
<p><label for="music">Search for a song:</label>
<input type="text" id="music" name="music"></p>
<button type="submit" name="form" value="submit">Search</button> <br>
<?php if(!isset($_POST["music"])) { echo "HINT: Ey bi si di i ef ci".
"eyc ay cey key elo meno pi".
"Q ar es ti yu vi".
"dabulyu x vay zet qapıcı izzet";} ?>
</form>
</div>
<?php
if(isset($_POST["music"])){
$songs = array("evde 5 arabada 15","topal","erik dali","cekirge","kapici izzet","dar geldi sana ankara");
$song = checkInput($_POST["music"]);
if(in_array(strtolower($song),$songs))
$result = '{"songs":[{"response":"Yes! We have that song..."}]}';
else
$result = '{"songs":[{"response":"' . $song . '??? Sorry, we don't have that song :("}]}';
}
else{
$result = '{"songss":"[{HINT: Ey bi si di i ef ci
eyc ay cey key elo meno pi
Q ar es ti yu vi
dabulyu x vay zet qapıcı izzet }]"}';
}
?>
<div class ="container" id="result"></div>
<script>
var JSONResponseString = '<?php echo $result ?>';
// var JSONResponse = eval ("(" + JSONResponseString + ")");
var JSONResponse = JSON.parse(JSONResponseString);
document.getElementById("result").innerHTML=JSONResponse.songs[0].response;
</script>
<!--
Level 0:
"}]}'; alert(1);//
---
<svg onload=alert(0)>
<a href=""> asd </a>
-->