mirror of
https://github.com/SquidSec/SquidGate
synced 2026-08-09 12:22:48 +00:00
sample(php): intentional vulnerabilities for SquidGate demo
Demo only — hardcoded secret + injection / dangerous API patterns. See examples/README.md
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
<?php
|
||||
// SquidGate sample — PHP (intentional vulnerabilities for demo)
|
||||
$api_key = "php-demo-secret-key-not-real";
|
||||
|
||||
function getUser($id) {
|
||||
// SQL injection
|
||||
$q = "SELECT * FROM users WHERE id = " . $_GET['id'];
|
||||
return mysqli_query($GLOBALS['db'], $q);
|
||||
}
|
||||
|
||||
function greet() {
|
||||
// XSS
|
||||
echo "Hello " . $_GET['name'];
|
||||
}
|
||||
|
||||
function run($code) {
|
||||
eval($code); // dangerous
|
||||
}
|
||||
Reference in New Issue
Block a user