Gist 6b1a5d43e458a795e475b14a5d9dbeac
✓ Published0🌍 Public
PPeleke
Last edited Oct 4, 2018
Created on Oct 4, 2018
This example demonstrates a malicious PHP file embedded within a GitHub gist, where an `echo` statement outputs `<h3>HACKED</h3>` to the page. The code uses the PHP `echo` language construct to directly inject HTML into the response, simulating a simple cross-site scripting or content injection attack. The gist syntax-highlights the PHP code, showing how a plain text file can carry executable server-side logic. The example highlights the security risk of trusting raw gist content, as the code appears as a static file but would execute if processed by a PHP-enabled server.
AI-generated description