# Introduction.
: BWAPP → Low → HTML Injection - reflected (GET)
# Training.
This 'html_get.php' is a page that prints the user's input value as follows.
data:image/s3,"s3://crabby-images/4dca1/4dca1c36b78ab065453021e2187551a153490320" alt=""
And If you check the URL, you can see that the input value and variable name are exposed in the URL. Because it is the GET method.
data:image/s3,"s3://crabby-images/60c6b/60c6b9feb9822400ef82496984f9624f28a66433" alt=""
In order to test the input items, I inserted HTML tags in the First name and Last name.
- <h1> Success</h1>
- <img src=http://192.168.10.119/bWAPP/images/bee_1.png>
data:image/s3,"s3://crabby-images/5687e/5687e9340a021179677514bb10403fd54eee5b2e" alt=""
The input result is as follows.
data:image/s3,"s3://crabby-images/48be4/48be490500a11ecca8ed53e7a823d517f8ff4abc" alt=""
data:image/s3,"s3://crabby-images/66bcb/66bcbaee9db8b8fb8b0a40f34cdd173edff29988" alt=""
No comments:
Post a Comment