| 104 |
admin
|
123456
|
|
| 457 |
admin
|
123456
|
|
| 460 |
admin
|
123456
|
|
| 474 |
admin
|
123456
|
|
| 475 |
admin
|
123456
|
|
| 489 |
admin
|
123456
|
|
| 491 |
admin
|
123456
|
|
| 494 |
admin
|
123456
|
|
| 498 |
/*1*/{{929526442+928904989}}
|
123456
|
|
| 503 |
admin
|
123456
|
|
| 509 |
admin
|
123456
|
|
| 511 |
admin
|
123456
|
|
| 514 |
admin
|
123456
|
|
| 517 |
${825852267+841785546}
|
123456
|
|
| 519 |
admin
|
123456
|
|
| 520 |
admin
|
123456
|
|
| 527 |
admin
|
123456
|
|
| 530 |
admin
|
123456
|
|
| 533 |
admin
|
123456
|
|
| 535 |
${(937127238+875063545)?c}
|
123456
|
|
| 538 |
admin
|
123456
|
|
| 540 |
admin
expr 981610279 + 870052559
|
123456
|
|
| 545 |
admin
|
123456
|
|
| 549 |
admin
|
123456
|
|
| 551 |
admin
|
123456
|
|
| 553 |
#set($c=868971404+961875464)${c}$c
|
123456
|
|
| 557 |
admin|expr 919515880 + 992048017
|
123456
|
|
| 558 |
admin
|
123456
|
|
| 563 |
${@var_dump(md5(821187377))};
|
123456
|
|
| 564 |
admin
|
123456
|
|
| 569 |
admin
|
123456/**/and+2=2
|
|
| 571 |
<%- 903598620+994857882 %>
|
123456
|
|
| 576 |
admin$(expr 813903520 + 921642806)
|
123456
|
|
| 577 |
admin
|
123456
|
|
| 580 |
'-var_dump(md5(817738436))-'
|
123456
|
|
| 582 |
admin
|
123456
|
|
| 587 |
admin
|
123456/**/and+4=9
|
|
| 589 |
admin
|
/*1*/{{951444994+962752457}}
|
|
| 594 |
${887671823+929741199}
|
123456
|
|
| 595 |
admin&set /A 859158569+835819053
|
123456
|
|
| 597 |
admin
|
${@var_dump(md5(192793623))};
|
|
| 599 |
admin
|
123456
|
|
| 606 |
admin
|
123456'and'c'='c
|
|
| 608 |
admin
|
${861656460+950021589}
|
|
| 609 |
admin
|
${993166161+991898214}
|
|
| 613 |
expr 867564982 + 803816516
|
123456
|
|
| 615 |
admin
|
'-var_dump(md5(868381313))-'
|
|
| 619 |
admin
|
123456
|
|
| 624 |
admin
|
123456'and'u'='l
|
|
| 625 |
admin
|
${(912978264+806928223)?c}
|
|
| 629 |
admin
|
123456
expr 811623882 + 847725219
|
|
| 630 |
admin
|
123456
|
|
| 634 |
admin
|
123456
|
|
| 640 |
admin
|
123456"and"p"="p
|
|
| 641 |
admin
|
#set($c=987011191+913539373)${c}$c
|
|
| 644 |
admin
|
123456|expr 999651020 + 913806275
|
|
| 645 |
admin
|
123456
|
|
| 650 |
admin
|
123456
|
|
| 655 |
admin
|
<%- 871626485+897303595 %>
|
|
| 657 |
admin
|
123456"and"e"="f
|
|
| 662 |
admin
|
123456$(expr 954382768 + 840760145)
|
|
| 665 |
admin
|
123456
|
|
| 670 |
admin
|
123456
|
|
| 675 |
admin
|
123456
|
|
| 676 |
admin
|
123456&set /A 894505259+983576614
|
|
| 681 |
admin
|
123456
|
|
| 687 |
admin
|
123456
|
|
| 690 |
admin
|
123456
|
|
| 691 |
admin
|
expr 818143749 + 900335546
|
|
| 696 |
admin
|
123456
|
|
| 703 |
admin
|
123456
|
|
| 705 |
admin
|
123456
|
|
| 706 |
admin
|
123456
|
|
| 711 |
admin
|
123456
|
|
| 718 |
admin
|
123456
|
|
| 720 |
admin
|
123456
|
|
| 721 |
admin
|
(select*from(select+sleep(0)union/**/select+1)a)
|
|
| 726 |
admin
|
123456
|
|
| 733 |
admin
|
123456
|
|
| 734 |
admin
|
123456
|
|
| 737 |
admin
|
(select*from(select+sleep(3)union/**/select+1)a)
|
|
| 740 |
admin
|
123456
|
|
| 746 |
admin
|
123456
|
|
| 748 |
admin
|
123456
|
|
| 752 |
admin
|
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
|
|
| 754 |
admin
|
123456
|
|
| 759 |
admin
|
123456
|
|
| 762 |
admin
|
123456
|
|
| 763 |
admin
|
123456'and(select*from(select+sleep(3))a/**/union/**/select+1)='
|
|
| 765 |
admin
|
123456
|
|
| 772 |
admin
|
123456
|
|
| 775 |
admin
|
123456
|
|
| 776 |
admin
|
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
|
|
| 782 |
admin
|
123456
|
|
| 785 |
admin
|
123456
|
|
| 788 |
admin
|
123456
|
|
| 791 |
admin
|
123456"and(select*from(select+sleep(3))a/**/union/**/select+1)="
|
|
| 792 |
admin
|
123456
|
|
| 797 |
admin
|
123456
|
|
| 800 |
admin
|
123456
|
|
| 803 |
admin
|
123456
|
|
| 805 |
admin
|
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
|
|
| 808 |
admin
|
123456
|
|
| 811 |
admin
|
123456
|
|
| 814 |
admin
|
123456
|
|
| 817 |
admin
|
123456/**/and(select+1/**/from/**/pg_sleep(3))>0/**/
|
|
| 819 |
admin
|
123456
|
|
| 822 |
admin
|
123456
|
|
| 826 |
admin
|
123456
|
|
| 827 |
admin
|
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
|
|
| 830 |
admin
|
123456
|
|
| 835 |
admin
|
123456
|
|
| 836 |
admin
|
123456'/**/and(select'1'from/**/pg_sleep(3))::text>'0
|
|
| 837 |
admin
|
123456
|
|
| 840 |
admin
|
123456
|
|
| 845 |
admin
|
123456
|
|
| 846 |
admin
|
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
|
|
| 848 |
admin
|
123456
|
|
| 850 |
admin
|
123456
|
|
| 855 |
admin
|
123456
|
|
| 857 |
admin
|
123456/**/and(select+1)>0waitfor/**/delay'0:0:3'/**/
|
|
| 859 |
admin
|
123456
|
|
| 861 |
admin
|
123456
|
|
| 863 |
admin
|
123456
|
|
| 865 |
admin
|
123456'and(select+1)>0waitfor/**/delay'0:0:0
|
|
| 869 |
admin
|
123456
|
|
| 872 |
admin
|
123456
|
|
| 873 |
admin
|
123456
|
|
| 875 |
admin
|
123456'and(select+1)>0waitfor/**/delay'0:0:3
|
|
| 878 |
admin
|
123456
|
|
| 882 |
admin
|
123456
|
|
| 886 |
admin
|
123456/**/and/**/1=DBMS_PIPE.RECEIVE_MESSAGE('q',0)
|
|
| 888 |
admin
|
123456
|
|
| 891 |
admin
|
123456
|
|
| 893 |
admin
|
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('u',3)
|
|
| 897 |
admin
|
123456
|
|
| 900 |
admin
|
123456
|
|
| 902 |
admin
|
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('i',0)='i
|
|
| 907 |
admin'and/**/extractvalue(1,concat(char(126),md5(1086195867)))and'
|
123456
|
|
| 912 |
admin
|
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('h',3)='h
|
|
| 916 |
admin"and/**/extractvalue(1,concat(char(126),md5(1492231420)))and"
|
123456
|
|
| 922 |
admin
|
123456
|
|
| 924 |
extractvalue(1,concat(char(126),md5(1951640089)))
|
123456
|
|
| 931 |
admin
|
123456
|
|
| 936 |
admin'and(select'1'from/**/cast(md5(1490227738)as/**/int))>'0
|
123456
|
|
| 942 |
admin
|
123456
|
|
| 947 |
admin/**/and/**/cast(md5('1023444813')as/**/int)>0
|
123456
|
|
| 953 |
admin
|
123456
|
|
| 959 |
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1148009669')))
|
123456
|
|
| 963 |
admin
|
123456
|
|
| 972 |
admin'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1240971038')))>'0
|
123456
|
|
| 975 |
admin
|
123456
|
|
| 983 |
admin鎈'"\(
|
123456
|
|
| 986 |
admin
|
123456
|
|
| 993 |
admin'"\(
|
123456
|
|
| 997 |
admin
|
123456
|
|
| 1001 |
admin
|
123456'and/**/extractvalue(1,concat(char(126),md5(1340147464)))and'
|
|
| 1008 |
admin
|
123456
|
|
| 1014 |
admin
|
123456"and/**/extractvalue(1,concat(char(126),md5(1380648497)))and"
|
|
| 1020 |
admin
|
123456
|
|
| 1025 |
admin
|
extractvalue(1,concat(char(126),md5(1457863174)))
|
|
| 1030 |
admin
|
123456
|
|
| 1035 |
admin
|
123456'and(select'1'from/**/cast(md5(1893030450)as/**/int))>'0
|
|
| 1041 |
admin
|
123456
|
|
| 1047 |
admin
|
123456/**/and/**/cast(md5('1544280316')as/**/int)>0
|
|
| 1054 |
admin
|
123456
|
|
| 1059 |
admin
|
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1047006160')))
|
|
| 1064 |
admin
|
123456
|
|
| 1069 |
admin
|
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1223460070')))>'0
|
|
| 1075 |
admin
|
123456
|
|
| 1082 |
admin
|
123456鎈'"\(
|
|
| 1086 |
admin
|
123456
|
|
| 1094 |
admin
|
123456'"\(
|
|
| 1096 |
admin
|
123456
|
|
| 1106 |
admin
|
123456
|
|
| 1108 |
admin
|
123456
|
|
| 1117 |
admin
|
123456
|
|
| 1119 |
admin
|
123456
|
|
| 1128 |
admin
|
123456
|
|
| 1129 |
admin
|
123456
|
|
| 1136 |
admin
|
123456
|
|
| 1137 |
admin
|
123456
|
|
| 1145 |
admin
|
123456
|
|
| 1147 |
admin
|
123456
|
|
| 1156 |
admin
|
123456
|
|
| 1158 |
admin
|
123456
|
|
| 1165 |
admin
|
123456
|
|
| 1168 |
admin
|
123456
|
|
| 1174 |
admin
|
123456
|
|
| 1178 |
admin
|
123456
|
|
| 1182 |
admin
|
123456
|
|
| 1189 |
admin
|
123456
|
|
| 1198 |
admin
|
123456
|
|
| 1207 |
admin
|
123456
|
|
| 1217 |
admin
|
123456
|
|
| 1226 |
admin
|
123456
|
|
| 1234 |
admin
|
123456
|
|
| 1242 |
admin
|
123456
|
|
| 1251 |
admin
|
123456
|
|
| 1259 |
admin
|
123456
|
|
| 1267 |
admin
|
123456
|
|
| 1275 |
admin
|
123456
|
|
| 1282 |
admin
|
123456
|
|
| 1291 |
admin
|
123456
|
|
| 1301 |
admin
|
123456
|
|
| 1311 |
admin
|
123456
|
|
| 1318 |
admin
|
123456
|
|
| 1325 |
admin
|
123456
|
|
| 1332 |
admin
|
123456
|
|
| 1340 |
admin
|
123456
|
|
| 1349 |
admin
|
123456
|
|
| 1359 |
admin
|
123456
|
|
| 1367 |
admin
|
123456
|
|
| 1376 |
admin
|
123456
|
|
| 1388 |
admin
|
123456
|
|
| 1400 |
admin
|
123456
|
|
| 1414 |
admin
|
123456
|
|
| 1426 |
admin
|
123456
|
|
| 1439 |
admin
|
123456
|
|
| 1452 |
admin
|
123456
|
|
| 1467 |
admin
|
123456
|
|
| 1480 |
admin
|
123456
|
|
| 1490 |
admin
|
123456
|
|
| 1503 |
admin
|
123456
|
|
| 1514 |
admin
|
123456
|
|
| 1525 |
admin
|
123456
|
|
| 1533 |
admin
|
123456
|
|
| 1543 |
admin
|
123456
|
|
| 1553 |
admin
|
123456
|
|
| 1563 |
admin
|
123456
|
|
| 1573 |
admin
|
123456
|
|
| 1583 |
admin
|
123456
|
|
| 1593 |
admin
|
123456
|
|
| 1603 |
admin
|
123456
|
|
| 1612 |
admin
|
123456
|
|
| 1622 |
admin
|
123456
|
|
| 1631 |
admin
|
123456
|
|
| 1642 |
admin
|
123456
|
|
| 1650 |
admin
|
123456
|
|
| 1658 |
admin
|
123456
|
|
| 1665 |
admin
|
123456
|
|
| 1674 |
admin
|
123456
|
|
| 1681 |
admin
|
123456
|
|
| 1688 |
admin
|
123456
|
|
| 1694 |
admin
|
123456
|
|
| 1700 |
admin
|
123456
|
|
| 1706 |
admin
|
123456
|
|
| 1712 |
admin
|
123456
|
|
| 1718 |
admin
|
123456
|
|
| 1724 |
admin
|
123456
|
|
| 1729 |
admin
|
123456
|
|
| 1733 |
admin
|
123456
|
|
| 1738 |
admin
|
123456
|
|
| 1742 |
admin
|
123456
|
|
| 1748 |
admin
|
123456
|
|
| 1752 |
admin
|
123456
|
|
| 1757 |
admin
|
123456
|
|
| 1762 |
admin
|
123456
|
|
| 1767 |
admin
|
123456
|
|
| 1772 |
admin
|
123456
|
|
| 1776 |
admin
|
123456
|
|
| 1781 |
admin
|
123456
|
|
| 1787 |
admin'and'f'='f
|
123456
|
|
| 1789 |
admin'and'b'='r
|
123456
|
|
| 1794 |
admin"and"z"="z
|
123456
|
|
| 1797 |
admin"and"c"="y
|
123456
|
|
| 1801 |
admin'and(select*from(select+sleep(0))a/**/union/**/select+1)='
|
123456
|
|
| 1804 |
admin'and(select*from(select+sleep(3))a/**/union/**/select+1)='
|
123456
|
|
| 1807 |
admin"and(select*from(select+sleep(0))a/**/union/**/select+1)="
|
123456
|
|
| 1810 |
admin"and(select*from(select+sleep(3))a/**/union/**/select+1)="
|
123456
|
|
| 1813 |
admin'/**/and(select'1'from/**/pg_sleep(0))::text>'0
|
123456
|
|
| 1816 |
admin'/**/and(select'1'from/**/pg_sleep(3))::text>'0
|
123456
|
|
| 1819 |
admin'and(select+1)>0waitfor/**/delay'0:0:0
|
123456
|
|
| 1822 |
admin'and(select+1)>0waitfor/**/delay'0:0:3
|
123456
|
|
| 1825 |
admin'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('u',0)='u
|
123456
|
|
| 1830 |
admin'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('a',3)='a
|
123456
|
|