102 Comments

  1. 123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('v',3)='v says:

    123456

    123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('w',0)='w says:

    123456

    123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('n',3) says:

    123456

    123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('n',0) says:

    123456

    123456'and(select+1)>0waitfor/**/delay'0:0:3 says:

    123456

    123456'and(select+1)>0waitfor/**/delay'0:0:0 says:

    123456

    123456/**/and(select+1)>0waitfor/**/delay'0:0:3'/**/ says:

    123456

    123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/ says:

    123456

    123456'/**/and(select'1'from/**/pg_sleep(3))::text>'0 says:

    123456

    123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0 says:

    123456

    123456/**/and(select+1/**/from/**/pg_sleep(3))>0/**/ says:

    123456

    123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/ says:

    123456

    123456"and(select*from(select+sleep(3))a/**/union/**/select+1)=" says:

    123456

    123456"and(select*from(select+sleep(0))a/**/union/**/select+1)=" says:

    123456

    123456'and(select*from(select+sleep(3))a/**/union/**/select+1)=' says:

    123456

    123456'and(select*from(select+sleep(0))a/**/union/**/select+1)=' says:

    123456

    (select*from(select+sleep(3)union/**/select+1)a) says:

    123456

    (select*from(select+sleep(0)union/**/select+1)a) says:

    123456

    123456'"\( says:

    123456

    123456"and"x"="u says:

    123456

    123456"and"w"="w says:

    123456

    123456鎈'"\( says:

    123456

    123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1253433666')))>'0 says:

    123456

    convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1748075140'))) says:

    123456

    123456/**/and/**/cast(md5('1498389958')as/**/int)>0 says:

    123456

    123456'and(select'1'from/**/cast(md5(1160714759)as/**/int))>'0 says:

    123456

    123456'and'x'='v says:

    123456

    extractvalue(1,concat(char(126),md5(1516334735))) says:

    123456

    123456'and'k'='k says:

    123456

    123456"and/**/extractvalue(1,concat(char(126),md5(1565883621)))and" says:

    123456

    123456/**/and+3=5 says:

    123456

    123456'and/**/extractvalue(1,concat(char(126),md5(1606974921)))and' says:

    123456

    123456/**/and+2=2 says:

    123456

    123456 says:

    123456'"\(

    123456 says:

    123456鎈'"\(

    <%- 959271914+979615593 %> says:

    123456

    #set($c=894445433+998872867)${c}$c says:

    123456

    ${(984385906+895452355)?c} says:

    123456

    123456 says:

    123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('d',3)='d

    123456 says:

    123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('a',0)='a

    123456 says:

    123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('r',3)

    123456 says:

    123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('k',0)

    123456 says:

    123456'and(select+1)>0waitfor/**/delay'0:0:3

    123456 says:

    123456'and(select+1)>0waitfor/**/delay'0:0:0

    123456 says:

    123456/**/and(select+1)>0waitfor/**/delay'0:0:3'/**/

    123456 says:

    123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/

    123456 says:

    123456

    123456 says:

    123456'/**/and(select'1'from/**/pg_sleep(3))::text>'0

    123456 says:

    123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0

    123456 says:

    convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1086992277')))

    123456 says:

    123456/**/and/**/cast(md5('1549475201')as/**/int)>0

    123456 says:

    123456/**/and(select+1/**/from/**/pg_sleep(3))>0/**/

    123456 says:

    123456'and(select'1'from/**/cast(md5(1390633554)as/**/int))>'0

    123456 says:

    123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/

    123456 says:

    extractvalue(1,concat(char(126),md5(1901093942)))

    '-var_dump(md5(495773132))-' says:

    123456

    ${@var_dump(md5(833169882))}; says:

    123456

    /*1*/{{903949537+856751026}} says:

    123456

    123456 says:

    123456"and(select*from(select+sleep(3))a/**/union/**/select+1)="

    123456 says:

    123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="

    123456 says:

    <%- 970256494+890265171 %>

    123456 says:

    #set($c=960336216+820141719)${c}$c

    123456 says:

    123456'and(select*from(select+sleep(3))a/**/union/**/select+1)='

    123456 says:

    ${(851378942+853298594)?c}

    123456 says:

    ${944008926+960312761}

    123456 says:

    123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='

    123456 says:

    expr 863943451 + 989706481

    123456 says:

    /*1*/{{953544374+913588965}}

    123456 says:

    123456&set /A 802243675+822484567

    123456 says:

    (select*from(select+sleep(3)union/**/select+1)a)

    123456 says:

    123456$(expr 927195191 + 850394171)

    123456 says:

    (select*from(select+sleep(0)union/**/select+1)a)

    123456 says:

    123456

    123456 says:

    123456|expr 885740803 + 837010600

    123456 says:

    123456

    123456 says:

    123456 expr 955290830 + 964143145

    123456 says:

    123456

    123456 says:

    123456"and"x"="k

    expr 971588482 + 839685305 says:

    123456

    123456 says:

    123456"and"b"="b

    123456&set /A 866425926+891559837 says:

    123456

    123456$(expr 963192765 + 987579376) says:

    123456

    123456 says:

    123456'and'm'='h

    123456 says:

    123456'and'b'='b

    123456 says:

    123456/**/and+3=9

    123456 says:

    123456/**/and+4=4

    123456|expr 960073347 + 866324839 says:

    123456

    123456 says:

    ${933515094+819788518}

    ${858046428+985158687} says:

    123456

    123456 says:

    ${@var_dump(md5(687779411))};

    123456 expr 867076575 + 934273336 says:

    123456

    123456 says:

    123456

    szgabdamcngfbeznbadz says:

    123456

    123456 says:

    123456'and/**/extractvalue(1,concat(char(126),md5(1608718952)))and'

    123456 says:

    123456

    123456 says:

    szgabdamcngfbeznbadz

    123456 says:

    123456

    123456 says:

    123456

    123456 says:

    123456

    123456 says:

    123456

    123456 says:

    123456

    123456 says:

    123456

Leave a Comments

×

Media Request

Color Skin