mirror of
https://github.com/SquidSec/SquidGate
synced 2026-08-09 12:22:48 +00:00
Demo only — hardcoded secret + injection / dangerous API patterns. See examples/README.md
19 lines
390 B
PHP
19 lines
390 B
PHP
<?php
|
|
// SquidGate sample — PHP (intentional vulnerabilities for demo)
|
|
$api_key = "php-demo-secret-key-not-real";
|
|
|
|
function getUser($id) {
|
|
// SQL injection
|
|
$q = "SELECT * FROM users WHERE id = " . $_GET['id'];
|
|
return mysqli_query($GLOBALS['db'], $q);
|
|
}
|
|
|
|
function greet() {
|
|
// XSS
|
|
echo "Hello " . $_GET['name'];
|
|
}
|
|
|
|
function run($code) {
|
|
eval($code); // dangerous
|
|
}
|