220 réponses

  1. « ;print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var= »

  2. ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))}

  3. ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))}\

  4. ; select « java.lang.Thread.sleep »(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = ‘SYSTEM_COLUMNS’ and COLUMN_NAME = ‘TABLE_NAME’ —

  5. ); select « java.lang.Thread.sleep »(15000) from INFORMATION_SCHEMA.SYSTEM_COLUMNS where TABLE_NAME = ‘SYSTEM_COLUMNS’ and COLUMN_NAME = ‘TABLE_NAME’ —

  6. Zaproxy dolore alias impedit expedita quisquam. / « java.lang.Thread.sleep »(15000)

  7. (SELECT UTL_INADDR.get_host_name(‘10.0.0.1’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.2’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.3’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.4’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.5’) from dual)

  8. Zaproxy dolore alias impedit expedita quisquam.’ / (SELECT UTL_INADDR.get_host_name(‘10.0.0.1’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.2’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.3’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.4’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.5’) from dual) / ‘

  9. Zaproxy dolore alias impedit expedita quisquam. and exists (SELECT UTL_INADDR.get_host_name(‘10.0.0.1’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.2’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.3’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.4’) from dual union SELECT UTL_INADDR.get_host_name(‘10.0.0.5’) from dual) —

  10. Zaproxy dolore alias impedit expedita quisquam.’ WAITFOR DELAY ‘0:0:15’ —

  11. « ;print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var= »

  12. ‘;print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110));$var=’

  13. ${@print(chr(122).chr(97).chr(112).chr(95).chr(116).chr(111).chr(107).chr(101).chr(110))}\

  14. #set($engine= » »)
    #set($proc=$engine.getClass().forName(« java.lang.Runtime »).getRuntime().exec(« sleep 0 »))
    #set($null=$proc.waitFor())
    ${null}

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *