<?php foreach($_GET as $k=>$v) { $_GET[$k]=htmlspecialchars($v); } echo "<table name=".$_GET['a']."><tr><td>test</td></tr></table>"; ?>
http://localhost/1.php.zzz?a=1%20onMouseOver=alert(/aaa/)
value="<?=$_GET?>"
<table name=1 onMouseOver=alert(/aaa/)><tr><td>test</td></tr></table>
<table name="1 onMouseOver=alert(/aaa/)"><tr><td>test</td></tr></table>