<slide title="XSS Types">
<break lines="8"/>
<blurb fontsize="5em">Unfiltered PHP_SELF/REQUEST_URI</blurb>
<example fontsize="1.6em" result="0"><![CDATA[<?php
$uri = getenv('REQUEST_URI');
$uri = $_SERVER['REQUEST_URI'];
$uri = $PHP_SELF;
?>
<a href="<?php echo $uri?>?page=2">Page 2</a>]]></example>

<example fontsize="1.75em" result="0"><![CDATA[http://search.secondlife.com/web/search/?q=test;"><script>alert(1)</script>]]></example>

</slide>
