<?php
// Reflects query param in HTML context (XSS sink)
$param = isset($_GET["param"]) ? $_GET["param"] : "";
$attr = isset($_GET["attr"]) ? $_GET["attr"] : "";
?>
<!DOCTYPE html>
<html>
<head><title>Reflect Test</title></head>
<body>
<h1>Reflection Test</h1>
<div id="html-context"><?php echo $param; ?></div>
<input type="text" value="<?php echo $attr; ?>">
<p>User-Agent: <?php echo $_SERVER["HTTP_USER_AGENT"] ?? ""; ?></p>
<p>X-Custom: <?php echo $_SERVER["HTTP_X_CUSTOM"] ?? ""; ?></p>
</body>
</html>
