it would only work if a variable of the same name existed, was used in a query string, and was not previously cleansed.
In a nutshell, it CAN happen - but its rare and really only through irresponsible coding or a complete oversight.
BTW: It couldnt happen the way you are trying to do it anyway. Why exactly are you posting this anyway? This is 'hacking' fodder which kind of concerns me.
|