sample(php): intentional vulnerabilities for SquidGate demo

Demo only — hardcoded secret + injection / dangerous API patterns.
See examples/README.md
This commit is contained in:
SquidSec Bot
2026-07-28 16:08:51 -04:00
parent ee7d42ee22
commit 189a5ee28f
+18
View File
@@ -0,0 +1,18 @@
<?php
// SquidGate sample — PHP (intentional vulnerabilities for demo)
$api_key = "php-demo-secret-key-not-real";
function getUser($id) {
// SQL injection
$q = "SELECT * FROM users WHERE id = " . $_GET['id'];
return mysqli_query($GLOBALS['db'], $q);
}
function greet() {
// XSS
echo "Hello " . $_GET['name'];
}
function run($code) {
eval($code); // dangerous
}