buy.php?id=4164970/printenv.shtml?alert('xss')