buy.php?id=4164970/ssi/printenv.shtml?alert('xss')