| 42 |
admin
|
123456
|
|
| 130 |
admin
|
123456
|
|
| 136 |
admin
|
123456
|
|
| 141 |
admin
|
123456
|
|
| 147 |
admin
|
123456
|
|
| 152 |
admin
|
123456
|
|
| 153 |
admin
|
123456
|
|
| 160 |
admin
|
123456
|
|
| 163 |
admin
|
123456
|
|
| 169 |
admin
|
123456
|
|
| 170 |
admin
|
123456
|
|
| 177 |
admin
|
123456
|
|
| 180 |
admin
|
123456
|
|
| 181 |
admin
|
123456
|
|
| 189 |
admin
|
123456
|
|
| 190 |
admin
|
123456
|
|
| 191 |
admin
|
123456
|
|
| 194 |
admin
|
123456
|
|
| 201 |
admin
|
123456
|
|
| 202 |
admin
|
123456
|
|
| 203 |
admin
|
123456
|
|
| 205 |
admin
|
123456
|
|
| 209 |
admin
|
123456
|
|
| 213 |
admin
|
123456
|
|
| 215 |
admin
|
123456
|
|
| 217 |
admin
|
123456
|
|
| 221 |
admin
|
123456
|
|
| 222 |
admin
|
123456
|
|
| 225 |
admin
|
123456
|
|
| 228 |
admin
|
123456
|
|
| 229 |
admin
|
123456
|
|
| 233 |
admin
|
123456
|
|
| 235 |
admin
|
123456
|
|
| 236 |
admin
|
123456
|
|
| 239 |
admin
|
123456
|
|
| 243 |
admin
|
123456
|
|
| 244 |
admin
|
123456
|
|
| 248 |
admin
|
123456
|
|
| 249 |
admin
|
123456
|
|
| 250 |
admin
|
123456
|
|
| 251 |
admin
|
123456
|
|
| 253 |
admin
|
123456
|
|
| 260 |
admin
|
123456
|
|
| 264 |
${897986402+807130807}
|
123456
|
|
| 265 |
admin
|
123456
|
|
| 266 |
admin
|
123456
|
|
| 267 |
admin
|
123456
|
|
| 271 |
admin
|
123456
|
|
| 275 |
${@var_dump(md5(783332231))};
|
123456
|
|
| 280 |
admin
|
${870371525+867896690}
|
|
| 281 |
admin
|
123456
|
|
| 284 |
admin
|
123456
|
|
| 286 |
admin
|
123456
|
|
| 288 |
'-var_dump(md5(146939515))-'
|
123456
|
|
| 290 |
admin
|
123456
|
|
| 295 |
admin
|
123456
|
|
| 297 |
admin
|
123456
|
|
| 298 |
admin
|
123456
|
|
| 301 |
admin
|
123456
|
|
| 307 |
admin
|
${@var_dump(md5(847417005))};
|
|
| 309 |
admin
|
123456
|
|
| 310 |
admin
|
123456
|
|
| 314 |
admin
|
123456
|
|
| 315 |
admin
|
123456
|
|
| 320 |
admin
|
123456
|
|
| 325 |
admin
|
'-var_dump(md5(792580489))-'
|
|
| 326 |
admin
|
123456
|
|
| 328 |
admin
|
123456
|
|
| 333 |
admin
|
123456
|
|
| 338 |
admin
|
123456
|
|
| 342 |
admin
|
123456
|
|
| 346 |
admin
|
123456
|
|
| 347 |
admin
|
123456
|
|
| 348 |
admin
|
123456
|
|
| 358 |
admin
|
123456
|
|
| 359 |
admin
|
123456
|
|
| 364 |
admin
|
123456
|
|
| 365 |
admin
|
123456
|
|
| 366 |
admin
|
123456
|
|
| 375 |
admin
|
123456
|
|
| 379 |
admin
|
123456
|
|
| 383 |
/*1*/{{982477546+946719537}}
|
123456
|
|
| 384 |
admin
|
123456
|
|
| 387 |
admin
|
123456
|
|
| 395 |
admin
|
123456
|
|
| 398 |
${941846399+924941444}
|
123456
|
|
| 404 |
admin
|
123456
|
|
| 406 |
admin
|
123456
|
|
| 413 |
admin
|
123456
|
|
| 416 |
${(920412440+983013768)?c}
|
123456
|
|
| 420 |
admin
|
123456
|
|
| 422 |
admin
|
123456
|
|
| 431 |
admin
|
123456
|
|
| 432 |
#set($c=879995608+973383134)${c}$c
|
123456
|
|
| 435 |
admin
|
123456
|
|
| 438 |
admin
|
123456
|
|
| 446 |
<%- 810227658+966116263 %>
|
123456
|
|
| 449 |
admin
|
123456
|
|
| 452 |
admin
|
123456
|
|
| 454 |
admin
|
123456
|
|
| 459 |
admin
|
/*1*/{{845565499+897188878}}
|
|
| 464 |
admin
expr 868635362 + 822442191
|
123456
|
|
| 468 |
admin
|
123456
|
|
| 469 |
admin
|
123456
|
|
| 473 |
admin
|
${991824903+965562022}
|
|
| 480 |
admin|expr 903191001 + 853141788
|
123456
|
|
| 482 |
admin
|
123456
|
|
| 484 |
admin
|
123456
|
|
| 488 |
admin
|
${(867387325+821323418)?c}
|
|
| 492 |
admin$(expr 852721427 + 872142185)
|
123456
|
|
| 501 |
admin
|
123456
|
|
| 502 |
admin
|
123456
|
|
| 505 |
admin
|
#set($c=803014820+921030309)${c}$c
|
|
| 506 |
admin&set /A 889042899+914894718
|
123456
|
|
| 518 |
admin
|
123456
|
|
| 522 |
admin
|
123456
|
|
| 523 |
expr 800522045 + 895085574
|
123456
|
|
| 524 |
admin
|
<%- 957097248+903769846 %>
|
|
| 536 |
admin
|
123456
|
|
| 539 |
admin
|
123456
|
|
| 541 |
admin
|
123456
expr 818795783 + 981537976
|
|
| 542 |
admin
|
123456
|
|
| 554 |
admin
|
123456|expr 942374366 + 949784773
|
|
| 556 |
admin
|
123456
|
|
| 559 |
admin
|
123456
|
|
| 560 |
admin
|
123456
|
|
| 572 |
admin
|
123456$(expr 896759489 + 832743631)
|
|
| 575 |
admin
|
123456
|
|
| 578 |
admin
|
123456
|
|
| 579 |
admin
|
123456
|
|
| 591 |
admin
|
123456&set /A 827829945+905156734
|
|
| 593 |
admin
|
123456
|
|
| 596 |
admin
|
123456
|
|
| 598 |
admin
|
123456
|
|
| 611 |
admin
|
expr 807410508 + 879673339
|
|
| 612 |
admin
|
123456
|
|
| 614 |
admin
|
123456
|
|
| 617 |
admin
|
123456
|
|
| 631 |
admin
|
123456
|
|
| 632 |
admin
|
123456
|
|
| 633 |
admin
|
123456
|
|
| 647 |
admin
|
123456
|
|
| 648 |
admin
|
123456
|
|
| 649 |
admin
|
123456
|
|
| 661 |
admin
|
123456
|
|
| 663 |
admin
|
123456
|
|
| 664 |
admin
|
123456
|
|
| 677 |
admin
|
123456
|
|
| 678 |
admin
|
123456
|
|
| 679 |
admin
|
123456
|
|
| 692 |
admin
|
123456
|
|
| 693 |
admin
|
123456
|
|
| 694 |
admin
|
123456
|
|
| 707 |
admin
|
123456
|
|
| 708 |
admin
|
123456
|
|
| 719 |
admin
|
123456
|
|
| 724 |
admin
|
123456
|
|
| 731 |
admin'and/**/extractvalue(1,concat(char(126),md5(1704310394)))and'
|
123456
|
|
| 736 |
admin
|
123456
|
|
| 745 |
admin"and/**/extractvalue(1,concat(char(126),md5(1138932048)))and"
|
123456
|
|
| 749 |
admin
|
123456
|
|
| 758 |
extractvalue(1,concat(char(126),md5(1950931748)))
|
123456
|
|
| 761 |
admin
|
123456
|
|
| 771 |
admin'and(select'1'from/**/cast(md5(1815655572)as/**/int))>'0
|
123456
|
|
| 774 |
admin
|
123456
|
|
| 784 |
admin/**/and/**/cast(md5('1559738061')as/**/int)>0
|
123456
|
|
| 787 |
admin
|
123456
|
|
| 796 |
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1943196001')))
|
123456
|
|
| 798 |
admin
|
123456
|
|
| 806 |
admin'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1531815601')))>'0
|
123456
|
|
| 809 |
admin
|
123456
|
|
| 816 |
admin鎈'"\(
|
123456
|
|
| 820 |
admin
|
123456
|
|
| 825 |
admin'"\(
|
123456
|
|
| 831 |
admin
|
123456
|
|
| 838 |
admin
|
123456'and/**/extractvalue(1,concat(char(126),md5(1832075782)))and'
|
|
| 842 |
admin
|
123456
|
|
| 847 |
admin
|
123456"and/**/extractvalue(1,concat(char(126),md5(1957301983)))and"
|
|
| 851 |
admin
|
123456
|
|
| 856 |
admin
|
extractvalue(1,concat(char(126),md5(1095073115)))
|
|
| 860 |
admin
|
123456
|
|
| 867 |
admin
|
123456'and(select'1'from/**/cast(md5(1953408915)as/**/int))>'0
|
|
| 870 |
admin
|
123456
|
|
| 879 |
admin
|
123456/**/and/**/cast(md5('1571587919')as/**/int)>0
|
|
| 881 |
admin
|
123456
|
|
| 887 |
admin
|
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1978047514')))
|
|
| 889 |
admin
|
123456
|
|
| 896 |
admin
|
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1965206425')))>'0
|
|
| 898 |
admin
|
123456
|
|
| 905 |
admin
|
123456鎈'"\(
|
|
| 909 |
admin
|
123456
|
|
| 915 |
admin
|
123456'"\(
|
|
| 918 |
admin
|
123456
|
|
| 927 |
admin
|
123456
|
|
| 938 |
admin
|
123456
|
|
| 945 |
admin
|
123456
|
|
| 955 |
admin
|
123456
|
|
| 966 |
admin
|
123456
|
|
| 978 |
admin
|
123456
|
|
| 990 |
admin
|
123456
|
|
| 1002 |
admin
|
123456
|
|
| 1013 |
admin
|
123456
|
|
| 1024 |
admin
|
123456
|
|
| 1034 |
admin
|
123456
|
|
| 1045 |
admin
|
123456
|
|
| 1056 |
admin
|
123456
|
|
| 1071 |
admin
|
123456
|
|
| 1080 |
admin
|
123456
|
|
| 1090 |
admin
|
123456
|
|
| 1101 |
admin
|
123456
|
|
| 1112 |
admin
|
123456
|
|
| 1123 |
admin
|
123456
|
|
| 1135 |
admin
|
123456
|
|
| 1146 |
admin
|
123456
|
|
| 1155 |
admin
|
123456
|
|
| 1167 |
admin
|
123456
|
|
| 1177 |
admin
|
123456
|
|
| 1186 |
admin
|
123456
|
|
| 1194 |
admin
|
123456
|
|
| 1204 |
admin
|
123456
|
|
| 1212 |
admin
|
123456
|
|
| 1224 |
admin
|
123456
|
|
| 1232 |
admin
|
123456
|
|
| 1241 |
admin
|
123456
|
|
| 1247 |
admin
|
123456
|
|
| 1255 |
admin
|
123456
|
|
| 1263 |
admin
|
123456
|
|
| 1271 |
admin
|
123456
|
|
| 1279 |
admin
|
123456
|
|
| 1287 |
admin
|
123456
|
|
| 1295 |
admin
|
123456
|
|
| 1303 |
admin
|
123456
|
|
| 1310 |
admin
|
123456
|
|
| 1319 |
admin
|
123456
|
|
| 1327 |
admin
|
123456
|
|
| 1333 |
admin
|
123456
|
|
| 1341 |
admin
|
123456
|
|
| 1350 |
admin
|
123456
|
|
| 1360 |
admin'and'm'='m
|
123456
|
|
| 1372 |
admin'and'k'='q
|
123456
|
|
| 1382 |
admin"and"e"="e
|
123456
|
|
| 1393 |
admin"and"c"="r
|
123456
|
|
| 1404 |
admin'and(select*from(select+sleep(0))a/**/union/**/select+1)='
|
123456
|
|
| 1413 |
admin'and(select*from(select+sleep(3))a/**/union/**/select+1)='
|
123456
|
|
| 1424 |
admin"and(select*from(select+sleep(0))a/**/union/**/select+1)="
|
123456
|
|
| 1437 |
admin"and(select*from(select+sleep(3))a/**/union/**/select+1)="
|
123456
|
|
| 1450 |
admin'/**/and(select'1'from/**/pg_sleep(0))::text>'0
|
123456
|
|
| 1462 |
admin'/**/and(select'1'from/**/pg_sleep(3))::text>'0
|
123456
|
|
| 1474 |
admin'and(select+1)>0waitfor/**/delay'0:0:0
|
123456
|
|
| 1485 |
admin'and(select+1)>0waitfor/**/delay'0:0:3
|
123456
|
|
| 1496 |
admin'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('n',0)='n
|
123456
|
|
| 1506 |
admin'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('z',3)='z
|
123456
|
|
| 1517 |
admin
|
123456/**/and+3=3
|
|
| 1528 |
admin
|
123456/**/and+4=5
|
|
| 1539 |
admin
|
123456'and'g'='g
|
|
| 1548 |
admin
|
123456'and'e'='f
|
|
| 1556 |
admin
|
123456"and"z"="z
|
|
| 1565 |
admin
|
123456"and"g"="i
|
|
| 1575 |
admin
|
(select*from(select+sleep(0)union/**/select+1)a)
|
|
| 1589 |
admin
|
(select*from(select+sleep(3)union/**/select+1)a)
|
|
| 1597 |
admin
|
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
|
|
| 1608 |
admin
|
123456'and(select*from(select+sleep(3))a/**/union/**/select+1)='
|
|
| 1619 |
admin
|
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
|
|
| 1628 |
admin
|
123456"and(select*from(select+sleep(3))a/**/union/**/select+1)="
|
|
| 1639 |
admin
|
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
|
|
| 1648 |
admin
|
123456/**/and(select+1/**/from/**/pg_sleep(3))>0/**/
|
|
| 1657 |
admin
|
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
|
|
| 1668 |
admin
|
123456'/**/and(select'1'from/**/pg_sleep(3))::text>'0
|
|
| 1675 |
admin
|
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
|
|
| 1682 |
admin
|
123456/**/and(select+1)>0waitfor/**/delay'0:0:3'/**/
|
|
| 1689 |
admin
|
123456'and(select+1)>0waitfor/**/delay'0:0:0
|
|
| 1695 |
admin
|
123456'and(select+1)>0waitfor/**/delay'0:0:3
|
|
| 1701 |
admin
|
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('b',0)
|
|
| 1707 |
admin
|
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('p',3)
|
|
| 1713 |
admin
|
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('l',0)='l
|
|
| 1719 |
admin
|
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('q',3)='q
|
|